#28488: Django 1.11 to 1.11.4 raises CSRF verification failed if settings.DEBUG
is
False
-------------------------------------+-------------------------------------
Reporter: Ruben Alves | Owner: nobody
Type: Bug | Status: new
Component: CSRF | Version: 1.11
Severity: Release blocker | Resolution:
Keywords: csrf failed | Triage Stage:
settings debug false production | Unreviewed
Has patch: 0 | Needs documentation: 0
Needs tests: 0 | Patch needs improvement: 0
Easy pickings: 0 | UI/UX: 0
-------------------------------------+-------------------------------------
Comment (by Ruben Alves):
Before Django1.11, I was using Django 1.8 and everything was working
perfectly.
In order to use Django1.11, I did all the changes mentioned on
https://docs.djangoproject.com/en/1.11/releases/1.11/
What I've done now was add `settings.CSRF_FAILURE_VIEW =
'courses.views.csrf_failure'` with `DEBUG=False`
I made my `courses.views.csrf_failure` raise an exception, so we could see
the traceback.
The traceback is the following:
File "/opt/python/run/venv/lib64/python2.7/site-
packages/django/core/handlers/exception.py" in inner
41. response = get_response(request)
File "/opt/python/run/venv/lib64/python2.7/site-
packages/django/core/handlers/base.py" in _legacy_get_response
249. response = self._get_response(request)
File "/opt/python/run/venv/lib64/python2.7/site-
packages/django/core/handlers/base.py" in _get_response
178. response = middleware_method(request, callback,
callback_args, callback_kwargs)
File "/opt/python/run/venv/lib64/python2.7/site-
packages/django/middleware/csrf.py" in process_view
314. return self._reject(request, REASON_BAD_TOKEN)
File "/opt/python/run/venv/lib64/python2.7/site-
packages/django/middleware/csrf.py" in _reject
163. return _get_failure_view()(request, reason=reason)
File "/opt/python/current/app/courses/views/__init__.py" in csrf_failure
49. raise Exception('Lets see where this shit works:' +
str(locals()))
--
Ticket URL: <https://code.djangoproject.com/ticket/28488#comment:3>
Django <https://code.djangoproject.com/>
The Web framework for perfectionists with deadlines.
--
You received this message because you are subscribed to the Google Groups
"Django updates" group.
To unsubscribe from this group and stop receiving emails from it, send an email
to [email protected].
To post to this group, send email to [email protected].
To view this discussion on the web visit
https://groups.google.com/d/msgid/django-updates/068.9ad16c54155c043e1d0e269f4455d94d%40djangoproject.com.
For more options, visit https://groups.google.com/d/optout.