Skip to content

Commit 75ff057

Browse files
author
Bernhard Posselt
committed
use normal login form for admin
1 parent 5dba0b6 commit 75ff057

File tree

2 files changed

+9
-1
lines changed

2 files changed

+9
-1
lines changed

CHANGELOG.md

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2,6 +2,12 @@
22

33
## [Unreleased]
44

5+
## [3.0.1] - 2017-11-15
6+
7+
### Security
8+
9+
- Require admin users to log in over the rate limited default login form
10+
511
## [3.0.0] - 2017-11-15
612

713
### Security

nextcloudappstore/urls.py

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,8 +5,8 @@
55
from django.conf.urls import url, include
66
from django.conf.urls.i18n import i18n_patterns
77
from django.contrib import admin
8+
from django.contrib.auth.decorators import login_required
89
from django.views.decorators.http import etag
9-
from django.views.generic import RedirectView
1010

1111
from nextcloudappstore.core.caching import app_rating_etag
1212
from nextcloudappstore.core.feeds import AppReleaseAtomFeed, AppReleaseRssFeed
@@ -15,6 +15,8 @@
1515
AppRegisterView
1616
from nextcloudappstore.scaffolding.views import AppScaffoldingView
1717

18+
admin.site.login = login_required(admin.site.login)
19+
1820
urlpatterns = [
1921
url(r'^$', CategoryAppListView.as_view(), {'id': None}, name='home'),
2022
url(r"^signup/$", csp_update(**settings.CSP_SIGNUP)(signup),

0 commit comments

Comments
 (0)