Only accept POST requests

1 parent 201a21f commit e1e1447b925562204272c6cb846a21195ad81c15 @paltman paltman committed
  1. +3 −1 reminders/
4 reminders/
@@ -1,8 +1,10 @@
from django.conf import settings
-from django.http import HttpResponse, Http404
+from django.http import HttpResponse, Http404, HttpResponseNotAllowed
def dismiss(request, label):
+ if request.method != "POST":
+ return HttpResponseNotAllowed(["POST"])
if label not in settings.REMINDERS:
return Http404()
if not settings.REMINDERS.get(label).get("dismissable", True):

