diff roundup/cgi/wsgi_handler.py @ 5218:44f7e6b958fe

Added tests for csrf with xmlrpc. Fixed the code for xmlrpc csrf defense: raise UsageError if X-REQUESTED-WITH header is required and missing. if HTTP_AUTHORIZATION is used, properly seed the random number generator using the password.
author John Rouillard <rouilj@ieee.org>
date Mon, 27 Mar 2017 22:37:30 -0400
parents 7aa72c31464d
children 92757447dcf0 35ea9b1efc14 ab37c1705dbf
line wrap: on
line diff

Roundup Issue Tracker: http://roundup-tracker.org/