|
17 | 17 | from django.views.decorators.debug import sensitive_post_parameters
|
18 | 18 |
|
19 | 19 | csrf_protect_m = method_decorator(csrf_protect)
|
| 20 | +sensitive_post_parameters_m = method_decorator(sensitive_post_parameters()) |
| 21 | + |
20 | 22 |
|
21 | 23 | class GroupAdmin(admin.ModelAdmin):
|
22 | 24 | search_fields = ('name',)
|
@@ -83,7 +85,7 @@ def get_urls(self):
|
83 | 85 | self.admin_site.admin_view(self.user_change_password))
|
84 | 86 | ) + super(UserAdmin, self).get_urls()
|
85 | 87 |
|
86 |
| - @sensitive_post_parameters() |
| 88 | + @sensitive_post_parameters_m |
87 | 89 | @csrf_protect_m
|
88 | 90 | @transaction.commit_on_success
|
89 | 91 | def add_view(self, request, form_url='', extra_context=None):
|
@@ -113,7 +115,7 @@ def add_view(self, request, form_url='', extra_context=None):
|
113 | 115 | return super(UserAdmin, self).add_view(request, form_url,
|
114 | 116 | extra_context)
|
115 | 117 |
|
116 |
| - @sensitive_post_parameters() |
| 118 | + @sensitive_post_parameters_m |
117 | 119 | def user_change_password(self, request, id, form_url=''):
|
118 | 120 | if not self.has_change_permission(request):
|
119 | 121 | raise PermissionDenied
|
@@ -170,4 +172,3 @@ def response_add(self, request, obj, post_url_continue='../%s/'):
|
170 | 172 |
|
171 | 173 | admin.site.register(Group, GroupAdmin)
|
172 | 174 | admin.site.register(User, UserAdmin)
|
173 |
| - |
|
0 commit comments