Monday, January 10, 2011

Re: Screen/Form Fields

> Pay attention to the notice about how this method (highest-ranked
> answer) doesn't actually remove it from the form, and a malicious user
> can still POST a value.

Why include it in the form if you can't change the value? Just pass the
thing you want to be display only to the page separately and then
display it using {{ TAG }}. If you're using a modelform, you can
specify a list of fields that you want to be included in the form -
that'll sort the malicious user problem.

Tim.

--
You received this message because you are subscribed to the Google Groups "Django users" group.
To post to this group, send email to django-users@googlegroups.com.
To unsubscribe from this group, send email to django-users+unsubscribe@googlegroups.com.
For more options, visit this group at http://groups.google.com/group/django-users?hl=en.

0 Comments:

Post a Comment

Subscribe to Post Comments [Atom]

<< Home


Real Estate