b839b2be31
Therefore, only raise Forbidden if Origin (or Referer for MSIE) is sent (which is a protected header and all modern browsers (except IE)). Also add a basic unit test which asserts the failure for false origins. |
||
---|---|---|
.. | ||
css | ||
db | ||
ext | ||
js | ||
utils | ||
views | ||
__init__.py | ||
compat.py | ||
core.py | ||
migrate.py | ||
wsgi.py |