1. 23 Sep, 2016 1 commit
  2. 18 Sep, 2016 6 commits
  3. 17 Sep, 2016 1 commit
  4. 15 Sep, 2016 1 commit
  5. 14 Sep, 2016 1 commit
    • Andrew Grigorev's avatar
      Fix CSRF for production deployments · db21a600
      Andrew Grigorev authored
      Current SecureForm implementation generates CSRF secret using
      `os.urandom()` every time when application start up. CSRF secret is used
      to calculate csrf_token check value, so if someone would use a command
      similar to
      
          gunicorn --workers=8 app
      
      to run his flask-admin app on production then most form submissions
      would silently fail (silently - as for now, it is probably another one
      bug).
      
      Instead of custom `os.urandom()` logic the `app.secret_key` value should
      be used to produce CSRF token values.
      db21a600
  6. 08 Sep, 2016 4 commits
  7. 05 Sep, 2016 3 commits
  8. 03 Sep, 2016 2 commits
  9. 31 Aug, 2016 2 commits
  10. 30 Aug, 2016 1 commit
  11. 28 Aug, 2016 1 commit
  12. 25 Aug, 2016 7 commits
  13. 16 Aug, 2016 1 commit
  14. 28 Jul, 2016 1 commit
  15. 26 Jul, 2016 1 commit
  16. 21 Jul, 2016 3 commits
  17. 17 Jul, 2016 3 commits
  18. 16 Jul, 2016 1 commit