Skip to content

0.6

Compare
Choose a tag to compare
@simonw simonw released this 01 Jul 00:46
  • Requests with an Authorization: Bearer xxx header are no longer subject to CSRF checks. #11
  • Requests without cookies are no longer subject to CSRF checks unless the page path is explicitly listed in always_protect. #11