Files
odoo_source/addons/payment_transfer/views
Christophe Simonis 7636b510a2 [ADD] *: CSRF protection in forms and routes
* make CSRF protection the default on all non-SAFE methods
  note: there currently is no way to call a CSRF-protected endpoint
  without a form-encoded entity-body as that's the only place we get the
  CSRF token from.
* simple CSRF token generation: just use the HMAC'd session id, no
  generating a new random token per session then HMAC it
* use constant-time equal function to avoid timing attacks
* assert that a database secret is configured before hashing/validating
  the CSRF token
* opt-out database manager from CSRF: The super-admin password serves
  the purpose of a CSRF token in the database manager screens.
  There is no request database to obtain the
  secret and generate a CSRF token.
2015-10-01 01:36:50 +02:00
..