Mercurial > p > roundup > code
diff roundup/security.py @ 5620:5f8e6034427c
Do not honor the X-HTTP-Method-Override if the original method used
was GET. GET's are supposed to be a safe operation. Require a non-GET
method (POST is suggested) in order for the override to occur.
| author | John Rouillard <rouilj@ieee.org> |
|---|---|
| date | Sun, 24 Feb 2019 21:34:17 -0500 |
| parents | 3fa026621f69 |
| children | 06e6bc21b67e |
