#28699: Problem with CSRF in Django 1.11.6
---------------------------------+------------------------------------
     Reporter:  stephanm         |                    Owner:  nobody
         Type:  Bug              |                   Status:  new
    Component:  CSRF             |                  Version:  1.11
     Severity:  Release blocker  |               Resolution:
     Keywords:                   |             Triage Stage:  Accepted
    Has patch:  0                |      Needs documentation:  0
  Needs tests:  0                |  Patch needs improvement:  0
Easy pickings:  0                |                    UI/UX:  0
---------------------------------+------------------------------------

Comment (by Florian Apolloner):

 > One strange thing I didn't understand: the csrf token in the returned
 json data and in the cookie are different

 Yes, the token changes every request to account for BREACH style attacks.
 you have to take the first half of it and xor it to the second one
 (basically) to get the constant "secret" behind it which is reused during
 the requests.

 As for your code:
 {{{
 from django.middleware.csrf import get_token
 get_token(request)
 }}}
 in your view should be enough, Django will take care of setting the cookie
 etc accordingly.

-- 
Ticket URL: <https://code.djangoproject.com/ticket/28699#comment:9>
Django <https://code.djangoproject.com/>
The Web framework for perfectionists with deadlines.

-- 
You received this message because you are subscribed to the Google Groups 
"Django updates" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To post to this group, send email to [email protected].
To view this discussion on the web visit 
https://groups.google.com/d/msgid/django-updates/066.5f6406396ef33cb3e1398d37033de8be%40djangoproject.com.
For more options, visit https://groups.google.com/d/optout.

Reply via email to