Comments (1)
We don't want to add plone4.csrffixes
in Plone 4.3 core. There are too many tests that would go wrong because of it. Those should only need changes in the tests, not in real code, but it is too much effort. So plone.protect
will remain officially at version 2.x
.
plone4.csrffixes
and plone.protect 3.x
are still recommended. Or you can edit your front webserver (likely nginx or Apache) to deny access to the ZMI
at manage
and manage_*
urls.
For most customers I have blocked access to the ZMI. For a few I have added plone4.csrffixes
.
from buildout.coredev.
Related Issues (20)
- Jenkins node 4 has problem with Python 3.6 and locales HOT 8
- Pillow >= 8.0.0 required for running coredev on M1 Macs HOT 8
- Pin cffi to 1.14.4 in order to avoid build failures on Apple M1 HOT 4
- Question: next steps in dev-stack? HOT 1
- Branch 6.0: Issue with portal_form_controller HOT 3
- Change default branch to 6.0 HOT 1
- Plone 6 should use latest zope.component, needs some test fixes HOT 2
- buildout freezes because of http links HOT 8
- Why does plone/documentation keep getting committed automatically? HOT 23
- POSSIBLE CHECKOUT ERROR plone/documentation 6-dev HOT 2
- Github Action broken in Plone 5.2 on Windows
- MacOS: error installing MarkupSafe in GitHub Actions HOT 2
- gh-actions: Windows buildout fails on z3c.relationfield HOT 2
- setting CORS headers HOT 2
- Plone 6.0 on Python 3.11 HOT 7
- buildout.coredev docs need to be pulled into Plone 6 Documentation HOT 12
- Python 2.7 got removed from Github Actions / setup-python HOT 1
- Set 6.1 as default branch on GitHub HOT 2
- bin/robot script is created from the robotframework entrypoint and not from plone.app.robotframework
- Problems with MacOS on GitHub Actions HOT 1
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from buildout.coredev.