mirror of
https://github.com/minetest/contentdb.git
synced 2025-01-03 03:37:28 +01:00
Remove CSRF token expiry
According to the OWASP, CSRF tokens don't need expiry times. They should be bound to the session. https://cheatsheetseries.owasp.org/cheatsheets/Cross-Site_Request_Forgery_Prevention_Cheat_Sheet.html#employing-hmac-csrf-tokens Fixes #437
This commit is contained in:
parent
63ad6a2b9a
commit
29a6a762cb
@ -75,6 +75,7 @@ app.config["FLATPAGES_EXTENSION"] = ".md"
|
|||||||
app.config["FLATPAGES_MARKDOWN_EXTENSIONS"] = MARKDOWN_EXTENSIONS
|
app.config["FLATPAGES_MARKDOWN_EXTENSIONS"] = MARKDOWN_EXTENSIONS
|
||||||
app.config["FLATPAGES_EXTENSION_CONFIG"] = MARKDOWN_EXTENSION_CONFIG
|
app.config["FLATPAGES_EXTENSION_CONFIG"] = MARKDOWN_EXTENSION_CONFIG
|
||||||
app.config["FLATPAGES_HTML_RENDERER"] = my_flatpage_renderer
|
app.config["FLATPAGES_HTML_RENDERER"] = my_flatpage_renderer
|
||||||
|
app.config["WTF_CSRF_TIME_LIMIT"] = None
|
||||||
|
|
||||||
app.config["BABEL_TRANSLATION_DIRECTORIES"] = "../translations"
|
app.config["BABEL_TRANSLATION_DIRECTORIES"] = "../translations"
|
||||||
app.config["LANGUAGES"] = {
|
app.config["LANGUAGES"] = {
|
||||||
|
Loading…
Reference in New Issue
Block a user