Skip to content

Exempt nested blueprints when the parent is CSRF-exempt - #701

Closed
gyanu2507 wants to merge 1 commit into
pallets-eco:mainfrom
gyanu2507:nested-csrf-parent-exempt
Closed

gyanu2507 wants to merge 1 commit into
pallets-eco:mainfrom
gyanu2507:nested-csrf-parent-exempt

Conversation

@gyanu2507

Copy link
Copy Markdown

_is_exempt only compared the current blueprint object, so a nested child like api.meta stayed protected after csrf.exempt(api).

Walk dotted names so an exempt parent covers its children.

Checklist:

  • Add tests that demonstrate the correct behavior of the change. Tests should fail without the change.
  • Add or update relevant docs, in the docs folder and in code.
  • Add an entry in docs/changes.rst summarizing the change and linking to the issue. Add .. versionchanged:: entries in any relevant code docs.

Walking dotted blueprint names means csrf.exempt(api) also covers api.meta.
@davidism davidism closed this Aug 28, 2026
@davidism

Copy link
Copy Markdown
Member

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

Add support for exemption on nested blueprints in CSRFProtect

2 participants