Remove CSRF TODO — closed as won't fix in #11

This commit is contained in:
2026-03-09 20:26:42 -06:00
parent 920463b4a7
commit d98dd1518b
-1
View File
@@ -73,7 +73,6 @@ with app.app_context():
@app.route('/', methods=['GET', 'POST']) @app.route('/', methods=['GET', 'POST'])
# TODO: No rate limiting — form can be spammed. Add Flask-Limiter (e.g. @limiter.limit("10/minute")). # TODO: No rate limiting — form can be spammed. Add Flask-Limiter (e.g. @limiter.limit("10/minute")).
# TODO: No CSRF protection. Add Flask-WTF for CSRF tokens.
def index(): def index():
error = None error = None
if request.method == 'POST': if request.method == 'POST':