Andreas Jaggi a752e0561d
Skip CSRF for embeds (#402)
* Skip CSRF for embeds

The CSRF middleware sets a _csrf cookie also for loading the embed
javascript on third-party sites. With this change no _csrf cookie is set
when loading the embed javascript (regardless if third-party site or
first-party).
2025-01-20 02:18:45 +01:00
..
2025-01-20 01:57:39 +01:00
2025-01-20 01:57:39 +01:00
2025-01-20 02:18:45 +01:00
2025-01-20 01:57:39 +01:00