# HG changeset patch # User Brian Neal # Date 1270324856 0 # Node ID 6a5549c2efb51acf41139fb464470cc724b66ac8 # Parent fa7d82bfb100f162efc6635d198354b1e85cbd82 Implement #62, add support for CSRF protection. diff -r fa7d82bfb100 -r 6a5549c2efb5 gpp/settings.py --- a/gpp/settings.py Sat Apr 03 02:15:04 2010 +0000 +++ b/gpp/settings.py Sat Apr 03 20:00:56 2010 +0000 @@ -76,6 +76,7 @@ if DEBUG: MIDDLEWARE_CLASSES = ( 'django.middleware.common.CommonMiddleware', + 'django.middleware.csrf.CsrfViewMiddleware', 'django.contrib.sessions.middleware.SessionMiddleware', 'django.contrib.messages.middleware.MessageMiddleware', 'debug_toolbar.middleware.DebugToolbarMiddleware', @@ -86,6 +87,7 @@ else: MIDDLEWARE_CLASSES = ( 'django.middleware.common.CommonMiddleware', + 'django.middleware.csrf.CsrfViewMiddleware', 'django.contrib.sessions.middleware.SessionMiddleware', 'django.contrib.messages.middleware.MessageMiddleware', 'django.contrib.auth.middleware.AuthenticationMiddleware', diff -r fa7d82bfb100 -r 6a5549c2efb5 gpp/templates/accounts/login.html --- a/gpp/templates/accounts/login.html Sat Apr 03 02:15:04 2010 +0000 +++ b/gpp/templates/accounts/login.html Sat Apr 03 20:00:56 2010 +0000 @@ -3,13 +3,12 @@ {% block content %}

Login

-
+{% csrf_token %} {{ form.as_table }}
 
-{% csrf_token %}