mirror of
https://github.com/encode/django-rest-framework.git
synced 2025-10-29 15:07:39 +03:00
Scripts with type="application/json" or "text/plain" are not executed, so we can use them to inject dynamic CSRF data, without allowing inline-script execution in Content-Security-Policy. |
||
|---|---|---|
| .. | ||
| admin | ||
| docs | ||
| filters | ||
| horizontal | ||
| inline | ||
| pagination | ||
| vertical | ||
| admin.html | ||
| api.html | ||
| base.html | ||
| login_base.html | ||
| login.html | ||
| raw_data_form.html | ||
| schema.js | ||