#28699: Problem with CSRF in Django 1.11.6
---------------------------------+------------------------------------
Reporter: stephanm | Owner: nobody
Type: Bug | Status: new
Component: CSRF | Version: 1.11
Severity: Release blocker | Resolution:
Keywords: | Triage Stage: Accepted
Has patch: 0 | Needs documentation: 0
Needs tests: 0 | Patch needs improvement: 0
Easy pickings: 0 | UI/UX: 0
---------------------------------+------------------------------------
Comment (by Florian Apolloner):
> One strange thing I didn't understand: the csrf token in the returned
json data and in the cookie are different
Yes, the token changes every request to account for BREACH style attacks.
you have to take the first half of it and xor it to the second one
(basically) to get the constant "secret" behind it which is reused during
the requests.
As for your code:
{{{
from django.middleware.csrf import get_token
get_token(request)
}}}
in your view should be enough, Django will take care of setting the cookie
etc accordingly.
--
Ticket URL: <https://code.djangoproject.com/ticket/28699#comment:9>
Django <https://code.djangoproject.com/>
The Web framework for perfectionists with deadlines.
--
You received this message because you are subscribed to the Google Groups
"Django updates" group.
To unsubscribe from this group and stop receiving emails from it, send an email
to [email protected].
To post to this group, send email to [email protected].
To view this discussion on the web visit
https://groups.google.com/d/msgid/django-updates/066.5f6406396ef33cb3e1398d37033de8be%40djangoproject.com.
For more options, visit https://groups.google.com/d/optout.