]> gitweb.ps.run Git - ps-cgit/commitdiff
authentication: use hidden form instead of referer
authorJason A. Donenfeld <Jason@zx2c4.com>
Thu, 16 Jan 2014 10:39:17 +0000 (11:39 +0100)
committerJason A. Donenfeld <Jason@zx2c4.com>
Thu, 16 Jan 2014 11:13:39 +0000 (12:13 +0100)
This also gives us some CSRF protection. Note that we make use of the
hmac to protect the redirect value.

Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>

No differences found