mirror of
https://github.com/django/django.git
synced 2025-10-31 09:41:08 +00:00
Fixed bug causing CSRF token not to rotate on login.
Thanks Gavin McQuillan for the report.
This commit is contained in:
@@ -56,7 +56,10 @@ def rotate_token(request):
|
||||
Changes the CSRF token in use for a request - should be done on login
|
||||
for security purposes.
|
||||
"""
|
||||
request.META["CSRF_COOKIE"] = _get_new_csrf_key()
|
||||
request.META.update({
|
||||
"CSRF_COOKIE_USED": True,
|
||||
"CSRF_COOKIE": _get_new_csrf_key(),
|
||||
})
|
||||
|
||||
|
||||
def _sanitize_token(token):
|
||||
|
||||
Reference in New Issue
Block a user