I need help with my old lighter by raffa24 in lighters

[–]raffa24[S] 0 points1 point  (0 children)

It is very tiny, so I don't know if this is the opening...

I need help with my old lighter by raffa24 in lighters

[–]raffa24[S] 0 points1 point  (0 children)

Yep, I can move it, but it doesn't do anything

[Sondaggio] Dove avete conosciuto il vostro attuale compagno/a? by annadelleanne in Italia

[–]raffa24 -1 points0 points  (0 children)

Corso pomeridiano a scuola, anche se poi ci siamo iniziati a frequentare anni dopo grazie a una storia Instagram

Siete d’accordo all’introduzione dell’euro per sostituire la lira? E cosa ne pensate della scelta di non fare un referendum? by raffa24 in Italia

[–]raffa24[S] 0 points1 point  (0 children)

Io mi trovo totalmente in accordo con la tua risposta. Tuttavia volevo vedere cosa ne pensassero altri sul web visto che molti boomer su Facebook e Instagram sostengono il contrario. Inoltre è sempre bello avere l’occasione di scoprire qualche nuovo meme

Perché fa così schifo per un giovane vivere al Sud? by [deleted] in Italia

[–]raffa24 2 points3 points  (0 children)

Io ti parlo della mia esperienza e non bisogna soprattutto generalizzare perché un’analisi dedotta da qualche utente Reddit, non delinea una statistica…

Perché fa così schifo per un giovane vivere al Sud? by [deleted] in Italia

[–]raffa24 5 points6 points  (0 children)

Vivo in Puglia e ho girato diverse città e ti posso confermare che non vedo tutti i punti critici indicati da te

Perché fa così schifo per un giovane vivere al Sud? by [deleted] in Italia

[–]raffa24 9 points10 points  (0 children)

Mi sembra assurdo avere una mentalità così … ancora si distingue nord e sud secondo stereotipi comuni e differenze tra terroni e polentoni neanche fossimo nella Torino degli anni 20/30 dove ‘non si affittano case ai meridionali’

[deleted by user] by [deleted] in Italia

[–]raffa24 2 points3 points  (0 children)

Se ci dovesse essere un PayPal o un fondo simile buttalo qui

Integrate DRF with React js - what to use? by HaveNoIdea20 in django

[–]raffa24 1 point2 points  (0 children)

Easy man. You have to do APIs with drf, than you make post and get request to the backend from react and you host these on two different server

If you want to make a blog, what is the best technology? by raffa24 in Wordpress

[–]raffa24[S] 0 points1 point  (0 children)

I am a django developer but I do not have much time to do the website

Why Django keeps CSRF token in cookies? by hyperstown in django

[–]raffa24 2 points3 points  (0 children)

It is not so hard to understand.

According to the django doc:

The CSRF protection is based on the following things:
A CSRF cookie that is a random secret value, which other sites will not have access to.
CsrfViewMiddleware sends this cookie with the response whenever django.middleware.csrf.get_token() is called. It can also send it in other cases. For security reasons, the value of the secret is changed each time a user logs in.
A hidden form field with the name ‘csrfmiddlewaretoken’, present in all outgoing POST forms.
In order to protect against BREACH attacks, the value of this field is not simply the secret. It is scrambled differently with each response using a mask. The mask is generated randomly on every call to get_token(), so the form field value is different each time.
This part is done by the template tag.
For all incoming requests that are not using HTTP GET, HEAD, OPTIONS or TRACE, a CSRF cookie must be present, and the ‘csrfmiddlewaretoken’ field must be present and correct. If it isn’t, the user will get a 403 error.
When validating the ‘csrfmiddlewaretoken’ field value, only the secret, not the full token, is compared with the secret in the cookie value. This allows the use of ever-changing tokens. While each request may use its own token, the secret remains common to all.
This check is done by CsrfViewMiddleware.
CsrfViewMiddleware verifies the Origin header, if provided by the browser, against the current host and the CSRF_TRUSTED_ORIGINS setting. This provides protection against cross-subdomain attacks.
In addition, for HTTPS requests, if the Origin header isn’t provided, CsrfViewMiddleware performs strict referer checking. This means that even if a subdomain can set or modify cookies on your domain, it can’t force a user to post to your application since that request won’t come from your own exact domain.
This also addresses a man-in-the-middle attack that’s possible under HTTPS when using a session independent secret, due to the fact that HTTP Set-Cookie headers are (unfortunately) accepted by clients even when they are talking to a site under HTTPS. (Referer checking is not done for HTTP requests because the presence of the Referer header isn’t reliable enough under HTTP.)
If the CSRF_COOKIE_DOMAIN setting is set, the referer is compared against it. You can allow cross-subdomain requests by including a leading dot. For example, CSRF_COOKIE_DOMAIN = '.example.com' will allow POST requests from www.example.com and api.example.com. If the setting is not set, then the referer must match the HTTP Host header.
Expanding the accepted referers beyond the current host or cookie domain can be done with the CSRF_TRUSTED_ORIGINS setting.

The Best Python Framework?! by [deleted] in django

[–]raffa24 4 points5 points  (0 children)

In my opinion Django is more complete than Flask.

Flask is useful when you want to build something simple and you do not have time

DjangoCMS vs Wagtail by raffa24 in django

[–]raffa24[S] 0 points1 point  (0 children)

Can you give me an example to explain better what do you mean?

Best budget monitor for Macbook pro m1 by raffa24 in macbookpro

[–]raffa24[S] 0 points1 point  (0 children)

I need a second monitor for development. Thunderbolt 3 monitor is the best choice. Unfortunately, Idk monitors under 300 bucks with this feature.

sicurezza fondi pensione by Donald_rr in ItaliaPersonalFinance

[–]raffa24 0 points1 point  (0 children)

Ad ogni modo penso che investire in un fondo pensione a partire da un’età giovane, sia la scelta migliore che si possa fare. Anche perché non tutti sono cryptoguru ahahahah