Close CSRF loophole (Closes #76)

- if you embed "/delete/memedaddy" into a page the link would get deleted
- this no longer is allowed
......@@ -329,7 +329,7 @@ def delete(request, short):
url = get_object_or_404(URL, short__iexact=short)
# If the RegisteredUser is the owner of the URL
if url.owner == request.user.registereduser:
if url.owner == request.user.registereduser and request.META['HTTP_REFERER'] == request.META['HTTP_HOST']:
# remove the URL
# redirect to my_links
