Comment 18 for bug 1463698

Revision history for this message
Matthias Runge (mrunge) wrote :

Horizon filters metadata by default. There still might be occurances, where filtering is not effective, i.e. when not using djangos template engine or filtering is explicitly switched off.

csrftoken is revealed at each form, but it's valid only once, and has to fit to the form location.