4 ms·
My Django is a little rusty but I think now requests will return 403s by default if you forget to include the csrf_token tag: https://docs.djangoproject.com/en/
by mac-chaffee 6y ago
My Django is a little rusty but I think now requests will return 403s by default if you forget to include the csrf_token tag: https://docs.djangoproject.com/en/3.0/ref/csrf/#rejected-requests https://docs.djangoproject.com/en/3.0/ref/csrf/#rejected-req...
Whereas the hand-rolled CSRF scheme I've inherited will fail silently
- silviogutierrez 6y agoThat's what I mean. If you forget to include the token on your app, it will fail. You have to remember to call {% csrf_token %} in every template. Back in the day, the middleware scanned your response and injected it next to each </form> tag. A hack and dirty for sure, but removed that burden.
- StavrosK 6y agoIt will fail securely, which is what you want. The alternative is to have it fail insecurely and bypass validation for everything. In the latest versions the framework sets the SameSite header properly, so you don't need the CSRF middleware at all (you can just remove it).