From c6c1d93c9881d8917f3ab6579f574ad655d11db3 Mon Sep 17 00:00:00 2001 From: Daniel STAN Date: Sat, 13 Jul 2013 18:43:33 +0200 Subject: [PATCH] [wiki] no redirect if "ticket" given MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit le paramètre ticket (ticket cas) interfère avec la suppression des fichiers, qui utilise aussi un ticket (ticket moinmoin) pour prévenir des csrf. --- wiki/auth/cas.py | 2 -- 1 file changed, 2 deletions(-) diff --git a/wiki/auth/cas.py b/wiki/auth/cas.py index 261c1edf..5ab2ec93 100644 --- a/wiki/auth/cas.py +++ b/wiki/auth/cas.py @@ -131,8 +131,6 @@ class CASAuth(BaseAuth): if not force and user_obj and user_obj.valid: if self.action == action: request.http_redirect(url) - if ticket: - request.http_redirect(url) return user_obj, True if self.ticket_path and request.method == 'POST':