def csrf_protect(): if request.method == "POST": token = session.pop('_csrf_token', None) if not token or token != request.form.get('_csrf_token'): abort(403)
def logout(): session.pop('logged_in', None) logout_user() return redirect(url_for('login'))
def logout(): logout_user() session.pop('username') return redirect(url_for('login'))