1. 26 Oct, 2016 2 commits
  2. 24 Oct, 2016 2 commits
  3. 23 Oct, 2016 3 commits
  4. 16 Oct, 2016 1 commit
  5. 11 Oct, 2016 2 commits
  6. 08 Oct, 2016 2 commits
  7. 04 Oct, 2016 1 commit
  8. 02 Oct, 2016 1 commit
  9. 30 Sep, 2016 1 commit
  10. 29 Sep, 2016 1 commit
  11. 23 Sep, 2016 4 commits
  12. 18 Sep, 2016 6 commits
  13. 17 Sep, 2016 2 commits
  14. 15 Sep, 2016 1 commit
  15. 14 Sep, 2016 1 commit
    • Andrew Grigorev's avatar
      Fix CSRF for production deployments · db21a600
      Andrew Grigorev authored
      Current SecureForm implementation generates CSRF secret using
      `os.urandom()` every time when application start up. CSRF secret is used
      to calculate csrf_token check value, so if someone would use a command
      similar to
      
          gunicorn --workers=8 app
      
      to run his flask-admin app on production then most form submissions
      would silently fail (silently - as for now, it is probably another one
      bug).
      
      Instead of custom `os.urandom()` logic the `app.secret_key` value should
      be used to produce CSRF token values.
      db21a600
  16. 10 Sep, 2016 1 commit
  17. 08 Sep, 2016 4 commits
  18. 05 Sep, 2016 3 commits
  19. 03 Sep, 2016 2 commits