plone / plone.protect

HTTP protection utilities for the Plone CMS
https://pypi.org/project/plone.protect/
7 stars 8 forks source link

don't worry about writes to session objects in the temporary storage #22

Closed davisagli closed 8 years ago

davisagli commented 8 years ago

This isn't ideal, but Zope sessions write all the time so flagging those writes for CSRF checks hoses the entire site.

vangheem commented 8 years ago

tests running here: http://jenkins.plone.org/job/pull-request-5.0/445/