Skip to content

Commit 93336bc

Browse files
committed

File tree

1 file changed

+6
-1
lines changed

1 file changed

+6
-1
lines changed

python/ql/lib/semmle/python/frameworks/Django.qll

Lines changed: 6 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2340,7 +2340,12 @@ module PrivateDjango {
23402340
}
23412341

23422342
override boolean getVerificationSetting() {
2343-
if list.getAnElt().(StrConst).getText() = "django.middleware.csrf.CsrfViewMiddleware"
2343+
if
2344+
list.getAnElt().(StrConst).getText() in [
2345+
"django.middleware.csrf.CsrfViewMiddleware",
2346+
// see https://github.com/mozilla/django-session-csrf
2347+
"session_csrf.CsrfMiddleware"
2348+
]
23442349
then result = true
23452350
else result = false
23462351
}

0 commit comments

Comments
 (0)