Package posterity :: Package web :: Module middleware :: Class CSRFMiddleware

Class CSRFMiddleware



object --+
         |
        CSRFMiddleware

WSGI filter that validates form tokens

A special hidden variable (_form_token) is used to protect the application against CSRF attacks. All submitted non-GET forms need to contain a valid form token. The form token value is a shared secret only known by the server and the end user.



Instance Methods
 
__init__(self, app)
x.__init__(...) initializes x; see x.__class__.__doc__ for signature
 
__call__(self, environ, start_response)

Inherited from object: __delattr__, __getattribute__, __hash__, __new__, __reduce__, __reduce_ex__, __repr__, __setattr__, __str__

Properties

Inherited from object: __class__

Method Details

__init__(self, app)
(Constructor)

 
x.__init__(...) initializes x; see x.__class__.__doc__ for signature
Overrides: object.__init__
(inherited documentation)