diff --git a/accounts/views.py b/accounts/views.py index a48b37c..fdaf1a3 100644 --- a/accounts/views.py +++ b/accounts/views.py @@ -6,7 +6,7 @@ from annoying.decorators import render_to from django.conf import settings from django.contrib.auth.decorators import login_required from django.core.mail import send_mail -from django.http import HttpResponseRedirect +from django.http import HttpResponseBadRequest, HttpResponseRedirect from snipts.models import Snipt @@ -22,6 +22,9 @@ def activate(request): if request.method == 'POST': + if 'token' not in request.POST: + return HttpResponseBadRequest() + token = request.POST['token'] stripe.api_key = os.environ.get('STRIPE_SECRET_KEY', settings.STRIPE_SECRET_KEY)