mirror of
https://github.com/cwinfo/powerdns-admin.git
synced 2025-02-07 01:06:16 +00:00
![corubba](/assets/img/avatar_default.png)
The CSRF token is currently inserted directly in the template and not in the browser via JavaScript from the cookie, so making it inaccessible is not a problem. The Sesson-cookie is already httponly by default [0]. [0] https://flask.palletsprojects.com/en/2.1.x/config/?highlight=session_cookie_httponly#SESSION_COOKIE_HTTPONLY