Skip to content
This repository was archived by the owner on Oct 22, 2019. It is now read-only.

Commit ee4185a

Browse files
committed
Added decorators to hide passwords for django error emails
1 parent 7dfb3d5 commit ee4185a

File tree

1 file changed

+7
-0
lines changed

1 file changed

+7
-0
lines changed

userena/views.py

+7
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,7 @@
44
from django.contrib.auth import get_user_model
55
from django.contrib.auth.forms import PasswordChangeForm
66
from django.contrib.auth.views import logout as Signout
7+
from django.views.decorators.debug import sensitive_post_parameters
78
from django.views.generic import TemplateView
89
from django.views.generic.list import ListView
910
from django.contrib import messages
@@ -69,6 +70,8 @@ def get_queryset(self):
6970
queryset = profile_model.objects.get_visible_profiles(self.request.user).select_related()
7071
return queryset
7172

73+
74+
@sensitive_post_parameters('password1', 'password2')
7275
@secure_required
7376
def signup(request, signup_form=SignupForm,
7477
template_name='userena/signup_form.html', success_url=None,
@@ -386,6 +389,8 @@ def disabled_account(request, username, template_name, extra_context=None):
386389
return ExtraContextTemplateView.as_view(template_name=template_name,
387390
extra_context=extra_context)(request)
388391

392+
393+
@sensitive_post_parameters('password')
389394
@secure_required
390395
def signin(request, auth_form=AuthenticationForm,
391396
template_name='userena/signin_form.html',
@@ -563,6 +568,8 @@ def email_change(request, username, email_form=ChangeEmailForm,
563568
return ExtraContextTemplateView.as_view(template_name=template_name,
564569
extra_context=extra_context)(request)
565570

571+
572+
@sensitive_post_parameters('old_password', 'new_password1', 'new_password2')
566573
@secure_required
567574
@permission_required_or_403('change_user', (get_user_model(), 'username', 'username'))
568575
def password_change(request, username, template_name='userena/password_form.html',

0 commit comments

Comments
 (0)