Merge pull request #81 from hiromi-mi/fix_csrf_authorize_follow
Add CSRF Protection in POST /authorize_follow
This commit is contained in:
commit
8df0ddb03a
1 changed files with 1 additions and 0 deletions
|
@ -639,6 +639,7 @@ def authorize_follow():
|
|||
)
|
||||
)
|
||||
|
||||
csrf.protect()
|
||||
actor = get_actor_url(request.form.get("profile"))
|
||||
if not actor:
|
||||
abort(500)
|
||||
|
|
Loading…
Add table
Add a link
Reference in a new issue