From 68d591c6770677e8a4de4c50984d7530b39bdfd7 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?P=C4=93teris=20Caune?= Date: Sun, 5 Mar 2017 22:14:09 +0200 Subject: [PATCH] No CSRF check for /bounce endpoint --- hc/api/views.py | 1 + 1 file changed, 1 insertion(+) diff --git a/hc/api/views.py b/hc/api/views.py index 2eb6a51c..36ce3a16 100644 --- a/hc/api/views.py +++ b/hc/api/views.py @@ -177,6 +177,7 @@ def badge(request, username, signature, tag): return HttpResponse(svg, content_type="image/svg+xml") +@csrf_exempt @uuid_or_400 def bounce(request, code): try: