Add global CSRF protection
This commit is contained in:
parent
ab09314ed3
commit
4ed522ae47
15 changed files with 28 additions and 22 deletions
|
@ -129,6 +129,9 @@ def make_pyramid_config(settings):
|
|||
config.set_authentication_policy(SessionAuthenticationPolicy())
|
||||
config.set_authorization_policy(TailboneAuthorizationPolicy())
|
||||
|
||||
# always require CSRF token protection
|
||||
config.set_default_csrf_options(require_csrf=True, token='_csrf')
|
||||
|
||||
# Bring in some Pyramid goodies.
|
||||
config.include('pyramid_beaker')
|
||||
config.include('pyramid_mako')
|
||||
|
|
Loading…
Add table
Add a link
Reference in a new issue