django-rest-framework/rest_framework/static
Luka Jeran 6ec6ddea9b
Avoid inline script execution for injecting CSRF token (#7016)
Scripts with type="application/json" or "text/plain" are not executed, so we can
use them to inject dynamic CSRF data, without allowing inline-script execution
in Content-Security-Policy.
2022-11-29 16:10:32 +00:00
..
rest_framework Avoid inline script execution for injecting CSRF token (#7016) 2022-11-29 16:10:32 +00:00