justingit / dada-mail

Self-Hosted, Full Featured, Email Mailing List Manager. Announcement + Discussion Lists, Web-based Installer, Installs with minimal dependencies, sendmail/SMTP/Amazon SES supported
https://dadamailproject.com
GNU General Public License v2.0
169 stars 40 forks source link

CSRF is set to "disable" in the "configure security options" section of the installer when installer is revisted #1132

Closed justingit closed 1 year ago

justingit commented 1 year ago

CSRF is still enabled by default, but if you do configure security options, it's set to be disabled by default (I think: needs verification)