1. 27 Oct, 2016 2 commits
  2. 26 Oct, 2016 2 commits
  3. 24 Oct, 2016 2 commits
  4. 23 Oct, 2016 3 commits
  5. 16 Oct, 2016 1 commit
  6. 11 Oct, 2016 2 commits
  7. 08 Oct, 2016 2 commits
  8. 04 Oct, 2016 1 commit
  9. 02 Oct, 2016 1 commit
  10. 30 Sep, 2016 1 commit
  11. 29 Sep, 2016 1 commit
  12. 23 Sep, 2016 4 commits
  13. 18 Sep, 2016 6 commits
  14. 17 Sep, 2016 2 commits
  15. 15 Sep, 2016 1 commit
  16. 14 Sep, 2016 1 commit
    • Andrew Grigorev's avatar
      Fix CSRF for production deployments · db21a600
      Andrew Grigorev authored
      Current SecureForm implementation generates CSRF secret using
      `os.urandom()` every time when application start up. CSRF secret is used
      to calculate csrf_token check value, so if someone would use a command
      similar to
      
          gunicorn --workers=8 app
      
      to run his flask-admin app on production then most form submissions
      would silently fail (silently - as for now, it is probably another one
      bug).
      
      Instead of custom `os.urandom()` logic the `app.secret_key` value should
      be used to produce CSRF token values.
      db21a600
  17. 10 Sep, 2016 1 commit
  18. 08 Sep, 2016 4 commits
  19. 05 Sep, 2016 3 commits