Changeset 6004
- Timestamp:
- 08/25/07 13:34:28 (1 year ago)
- Files:
-
- django/trunk/AUTHORS (modified) (1 diff)
- django/trunk/django/contrib/auth/views.py (modified) (1 diff)
Legend:
- Unmodified
- Added
- Removed
- Modified
- Copied
- Moved
django/trunk/AUTHORS
r5990 r6004 95 95 deric@monowerks.com 96 96 Max Derkachev <mderk@yandex.ru> 97 Sander Dijkhuis <sander.dijkhuis@gmail.com> 97 98 Jordan Dimov <s3x3y1@gmail.com> 98 99 dne@mayonnaise.net django/trunk/django/contrib/auth/views.py
r5886 r6004 18 18 if not errors: 19 19 # Light security check -- make sure redirect_to isn't garbage. 20 if not redirect_to or ' ://' in redirect_to or ' ' in redirect_to:20 if not redirect_to or '//' in redirect_to or ' ' in redirect_to: 21 21 from django.conf import settings 22 22 redirect_to = settings.LOGIN_REDIRECT_URL
