Disable anti-csrf on the login form
The rationale is that the attacker doesn't have the password... and that doing it this way we avoid creating useless sessionsmaster
parent
481cb67392
commit
64d757582d
Loading…
Reference in New Issue