Mariusz Felisiak
|
e01970e9d2
Refs #32800 -- Removed CSRF_COOKIE_MASKED transitional setting per deprecation timeline.
|
2 anni fa |
Claude Paroz
|
93803a1b5f
Fixed #33567 -- Avoided setting default text/html content type on responses.
|
3 anni fa |
Mariusz Felisiak
|
7119f40c98
Refs #33476 -- Refactored code to strictly match 88 characters line length.
|
3 anni fa |
django-bot
|
9c19aff7c7
Refs #33476 -- Reformatted code with Black.
|
3 anni fa |
Chris Jerdonek
|
3ff7f6cf07
Refs #32800 -- Renamed _sanitize_token() to _check_token_format().
|
3 anni fa |
Chris Jerdonek
|
5d80843ebc
Fixed #32800 -- Changed CsrfViewMiddleware not to mask the CSRF secret.
|
3 anni fa |
Chris Jerdonek
|
3f0025c18a
Refs #32800 -- Avoided use of _does_token_match() in some CSRF tests.
|
3 anni fa |
Chris Jerdonek
|
0820175d81
Refs #32800 -- Added CSRF tests for masked and unmasked secrets during GET.
|
3 anni fa |
Chris Jerdonek
|
be1fd6645d
Refs #32800 -- Added test_masked_secret_accepted_and_not_replaced().
|
3 anni fa |
Chris Jerdonek
|
7aba820aca
Refs #32800 -- Improved CsrfViewMiddlewareTestMixin._check_token_present().
|
3 anni fa |
Chris Jerdonek
|
26d8e3f302
Refs #32800 -- Used the cookie argument to CsrfViewMiddlewareTestMixin._get_request() in more tests.
|
3 anni fa |
Chris Jerdonek
|
795051b2b0
Refs #32800 -- Added tests of more CSRF functions.
|
3 anni fa |
Chris Jerdonek
|
7132341255
Refs #32800 -- Renamed _compare_masked_tokens() to _does_token_match().
|
3 anni fa |
Virtosu Bogdan
|
00ea883ef5
Fixed #32329 -- Made CsrfViewMiddleware catch more specific UnreadablePostError.
|
3 anni fa |
Virtosu Bogdan
|
852fa7617e
Refs #32329 -- Allowed specifying request class in csrf_tests test hooks.
|
3 anni fa |
Chris Jerdonek
|
a2e1f1e295
Fixed #32902 -- Fixed CsrfViewMiddleware.process_response()'s cookie reset logic.
|
3 anni fa |
Chris Jerdonek
|
311401d9a2
Refs #32902 -- Added CSRF test when rotate_token() is called between resetting the token and processing response.
|
3 anni fa |
Chris Jerdonek
|
43d1ea6e2f
Refs #32885 -- Used _read_csrf_cookie()/_set_csrf_cookie() in more CSRF tests.
|
3 anni fa |
Chris Jerdonek
|
abc8795632
Fixed #32885 -- Removed cookie-based token specific logic from CsrfViewMiddlewareTestMixin.
|
3 anni fa |
Chris Jerdonek
|
594d6e9407
Refs #32843 -- Added CsrfViewMiddlewareTestMixin._get_csrf_cookie_request() hook.
|
3 anni fa |
Chris Jerdonek
|
c8439d1dba
Refs #32843 -- Added method/cookie arguments to CsrfViewMiddlewareTestMixin._get_request().
|
3 anni fa |
Chris Jerdonek
|
6bccb64347
Refs #32843 -- Moved _get_GET_csrf_cookie_request() to CsrfViewMiddlewareTestMixin.
|
3 anni fa |
Chris Jerdonek
|
4397d2bd6b
Fixed #32843 -- Ensured the CSRF tests' _get_GET_csrf_cookie_request() sets the request method.
|
3 anni fa |
Chris Jerdonek
|
5e60c3943b
Refs #32800 -- Added CsrfViewMiddleware tests for all combinations of masked/unmasked cookies and tokens.
|
3 anni fa |
Chris Jerdonek
|
defa8d3d87
Refs #32800 -- Made CsrfViewMiddlewareTestMixin._csrf_id_cookie and _csrf_id_token different.
|
3 anni fa |
Chris Jerdonek
|
2523c32d50
Refs #32800 -- Eliminated the need for separate _get_POST_bare_secret() methods.
|
3 anni fa |
Chris Jerdonek
|
c8108591b9
Refs #32800 -- Added to csrf_tests/tests.py the unmasked version of the secret.
|
3 anni fa |
Chris Jerdonek
|
fcb75651f9
Fixed #32817 -- Added the token source to CsrfViewMiddleware's bad token error messages.
|
3 anni fa |
Chris Jerdonek
|
1a284afb07
Refs #32817 -- Added tests for bad CSRF token provided via X-CSRFToken or custom header.
|
3 anni fa |
Chris Jerdonek
|
6837bd68a4
Refs #32817 -- Added post_token/meta_token/token_header arguments to _get_POST_csrf_cookie_request().
|
3 anni fa |