3 ms·
The CSRF token can have nothing to do with the cookie session information. you can store CSRF as a separate cookie. You can validate the CSRF is valid by keepi
by hansonkd 2y ago
The CSRF token can have nothing to do with the cookie session information. you can store CSRF as a separate cookie.
You can validate the CSRF is valid by keeping a key on your server and matching that the token you get can be derived from that key.
See Django's implementation of CSRF for more details. CSRF tokens are separate from session and no CSRF information needs to be stored in database to validate CSRF.