Files
zulip/templates/zephyr/logout.html
Reid Barton 6bb9ad4e3c Avoid cross-site logout attacks
Require POST method for /accounts/logout. This has the side effect of
automatically enabling Django's CSRF protection.

(imported from commit 44b1b6ebaadc1c03006e21ae54ac768e31234801)
2013-03-06 19:10:04 -05:00

5 lines
121 B
HTML

<div class="hidden">
<form id="logout_form" action="/accounts/logout/" method="POST">{% csrf_token %}
</form>
</div>