liquid_feedback_frontend

diff model/session.lua @ 1494:3e9b0f1adec3

Removed token based CSRF protection (WebMCP uses SameSite cookies now)
author bsw
date Mon Dec 09 15:54:57 2019 +0100 (2019-12-09)
parents 32cc544d5a5b
children f1258993d993
line diff
     1.1 --- a/model/session.lua	Mon Aug 26 15:55:48 2019 +0200
     1.2 +++ b/model/session.lua	Mon Dec 09 15:54:57 2019 +0100
     1.3 @@ -20,7 +20,7 @@
     1.4  
     1.5  local secret_length = 24
     1.6  local secret_alphabet = '0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz'
     1.7 -local secret_purposes = { "oauth", "csrf", "_other" }
     1.8 +local secret_purposes = { "oauth", "_other" }
     1.9  for idx, purpose in ipairs(secret_purposes) do
    1.10    secret_purposes[purpose] = idx
    1.11  end

Impressum / About Us