Permalink
Browse files

Add decorator to block non-POST requests on login

  • Loading branch information...
ramonakira committed Feb 7, 2013
1 parent f20fada commit 4ce0096ef5817b9242fd9aa8a67a5333c9659548
Showing with 2 additions and 0 deletions.
  1. +2 −0 fiber/admin_views.py
View
@@ -1,4 +1,5 @@
from django.contrib.admin.views.decorators import staff_member_required
+from django.views.decorators.http import require_POST
from django.contrib.auth import authenticate, login
from django.http import HttpResponse, HttpResponseRedirect
from django.utils import simplejson
@@ -7,6 +8,7 @@
from .models import Page
+@require_POST
def fiber_login(request):
username = request.POST['username']
password = request.POST['password']

0 comments on commit 4ce0096

Please sign in to comment.