mirror of
https://github.com/encode/django-rest-framework.git
synced 2025-11-02 08:57:43 +03:00
Scripts with type="application/json" or "text/plain" are not executed, so we can use them to inject dynamic CSRF data, without allowing inline-script execution in Content-Security-Policy. |
||
|---|---|---|
| .. | ||
| ajax-form.js | ||
| bootstrap.min.js | ||
| coreapi-0.1.1.js | ||
| csrf.js | ||
| default.js | ||
| jquery-3.5.1.min.js | ||
| prettify-min.js | ||