Files
ports/www/py-django-debreach/pkg-descr
T
2026-10-04 04:07:15 +00:00

9 lines
415 B
Plaintext

Basic/extra mitigation against the BREACH attack for Django projects.
django-debreach provides additional protection to Django's built in CSRF token
masking by randomizing the content length of each response.
This is achieved by adding a random string of between 12 and 25 characters as a
comment to the end of the HTML content. Note that this will only be applied to
responses with a content type of text/html.