Commit History

Autor SHA1 Mensaxe Data
  Tim Graham 4965a77407 Removed PIL compatability layer per deprecation timeline. %!s(int64=11) %!d(string=hai) anos
  Tim Graham df6760f12c Added a warning regarding risks in serving user uploaded media. %!s(int64=11) %!d(string=hai) anos
  Tim Graham a3372f67cb Added a warning regarding session security and subdomains. %!s(int64=11) %!d(string=hai) anos
  Aymeric Augustin 1267d2d9bc Fixed #20330 -- Normalized spelling of "web server". %!s(int64=12) %!d(string=hai) anos
  Carl Meyer d51fb74360 Added a new required ALLOWED_HOSTS setting for HTTP host header validation. %!s(int64=12) %!d(string=hai) anos
  Aymeric Augustin ebd2598596 Removed django.contrib.markup. %!s(int64=12) %!d(string=hai) anos
  Tim Graham b3a8c9dab8 Fixed broken links, round 3. refs #19516 %!s(int64=12) %!d(string=hai) anos
  Florian Apolloner 27560924ec Fixed a security issue in get_host. %!s(int64=12) %!d(string=hai) anos
  David Fischer 58786897a1 Formatting fix for host headers section %!s(int64=12) %!d(string=hai) anos
  David Fischer c65100248d Added CSRF with HTTPS/HSTS and forwarding note %!s(int64=12) %!d(string=hai) anos
  David Fischer ba141e6906 Added note about Strict Transport Security (HSTS) %!s(int64=12) %!d(string=hai) anos
  Luke Plant 0199bdc0b4 Rewrote security.txt SSL docs, noting SECURE_PROXY_SSL_HEADER. %!s(int64=13) %!d(string=hai) anos
  Luke Plant 718f149bb2 Added more explicit warnings about unconfigured reStructured Text usage in docs. %!s(int64=13) %!d(string=hai) anos
  Adrian Holovaty d3055b3382 Quick edit of docs/topics/security.txt to catch some basic formatting problems and reword an awkward section %!s(int64=13) %!d(string=hai) anos
  Russell Keith-Magee 893cea211a Added protection against spoofing of X_FORWARDED_HOST headers. A security announcement will be made shortly. %!s(int64=13) %!d(string=hai) anos
  Jannis Leidel f0280f2e94 Fixes #16482 -- Fixes typo in security docs. Thanks, charettes. %!s(int64=13) %!d(string=hai) anos
  Luke Plant 9896b0df73 Grammar fixes and content tweaks to XSS section of security docs. %!s(int64=13) %!d(string=hai) anos
  Luke Plant f5c9c2246e Improved warning about file uploads in docs, and added link from security overview page %!s(int64=13) %!d(string=hai) anos
  Jannis Leidel 3ee076b135 Fixed #16248 -- Corrected a few typos in the security docs. Thanks, buddelkiste. %!s(int64=13) %!d(string=hai) anos
  Luke Plant 528157ce73 Fixed #14201 - Add a "security overview" page to the docs %!s(int64=14) %!d(string=hai) anos