]> git.ipfire.org Git - ipfire.org.git/commitdiff
auth: Do not cache registration page because of XSRF cookie
authorMichael Tremer <michael.tremer@ipfire.org>
Mon, 9 Dec 2019 20:20:58 +0000 (20:20 +0000)
committerMichael Tremer <michael.tremer@ipfire.org>
Mon, 9 Dec 2019 20:20:58 +0000 (20:20 +0000)
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
src/web/auth.py

index 56f4b32f211a4aa9ecfade330f5a3386250f3af5..a81b6f263139b7769dc2aeaf32c05d9ddc9b8bed 100644 (file)
@@ -81,7 +81,7 @@ class LogoutHandler(AuthenticationMixin, base.BaseHandler):
                self.redirect("/")
 
 
-class RegisterHandler(base.BaseHandler):
+class RegisterHandler(CacheMixin, base.BaseHandler):
        def get(self):
                # Redirect logged in users away
                if self.current_user:
@@ -143,7 +143,7 @@ class ActivateHandler(AuthenticationMixin, base.BaseHandler):
                self.render("auth/activated.html", account=account)
 
 
-class PasswordResetInitiationHandler(base.BaseHandler):
+class PasswordResetInitiationHandler(CacheMixin, base.BaseHandler):
        def get(self):
                username = self.get_argument("username", None)