Skip to content

CSRF Trusted Origins #2909

@sixcolors

Description

@sixcolors

A possible solution that maintains best practice for CSRF protection while addressing some users issue where they have multilple origins that they consider trusted, could be to mirror https://docs.djangoproject.com/en/5.0/ref/settings/#std-setting-CSRF_TRUSTED_ORIGINS

Originally posted by @sixcolors in #2904 (review)

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    Status

    Done

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions