mirror of
https://github.com/encode/django-rest-framework.git
synced 2024-11-25 11:04:02 +03:00
6ec6ddea9b
Scripts with type="application/json" or "text/plain" are not executed, so we can use them to inject dynamic CSRF data, without allowing inline-script execution in Content-Security-Policy. |
||
---|---|---|
.. | ||
admin | ||
docs | ||
filters | ||
horizontal | ||
inline | ||
pagination | ||
vertical | ||
admin.html | ||
api.html | ||
base.html | ||
login_base.html | ||
login.html | ||
raw_data_form.html | ||
schema.js |