#28699: Problem with CSRF in Django 1.11.6
---------------------------------+------------------------------------
     Reporter:  stephanm         |                    Owner:  nobody
         Type:  Bug              |                   Status:  new
    Component:  CSRF             |                  Version:  1.11
     Severity:  Release blocker  |               Resolution:
     Keywords:                   |             Triage Stage:  Accepted
    Has patch:  0                |      Needs documentation:  0
  Needs tests:  0                |  Patch needs improvement:  0
Easy pickings:  0                |                    UI/UX:  0
---------------------------------+------------------------------------

Comment (by stephanm):

 Hi,

 I restored the original Django 1.11.6  and moved the lines you mentioned
 *before* before the CSRF middleware and I can confirm that **it works
 now**!

 Concerning my C# Application, It calls the following
 function in my views.py with a GET call to
 get the carf_token:
 {{{#!python
 def auth_get_csrf_token_json(request):
     token = csrf(request)
     csrf_token = str(token["csrf_token"])  # ab django 1.5
     response = JsonResponse({"dataType": "csrf", "data": {"csrftoken":
 csrf_token}})
     # I set the cookie in the past but it seems not necessary
     ##response.set_cookie("csrftoken", csrf_token)
     return response
 }}}

 Note:
  - I send back the csrf token in as json data but in
    my C# app I use the csrf token which is in the **cookie**.
  - One strange thing I didn't understand: the csrf token
    in the returned json data and in the cookie are **different**

 Honestly I was never sure where to get this **initial** csrf token
 to be able to POST my login data.
 So I did my experiments until I found this solution which worked for me
 (some times ago).

-- 
Ticket URL: <https://code.djangoproject.com/ticket/28699#comment:8>
Django <https://code.djangoproject.com/>
The Web framework for perfectionists with deadlines.

-- 
You received this message because you are subscribed to the Google Groups 
"Django updates" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To post to this group, send email to [email protected].
To view this discussion on the web visit 
https://groups.google.com/d/msgid/django-updates/066.04eb6bbee96e6b4a984e5bcdf2ffbc6d%40djangoproject.com.
For more options, visit https://groups.google.com/d/optout.

Reply via email to