Thursday, April 25, 2019

Re: CSRF Verification fails in production for Cross Domain POST request

When I have problems with csrf and POST, I usually put a  print(request.POST) into a view function, to see what the framework recives from client

help you?


Missatge de suresh <sureshvv@hotmail.com> del dia dj., 25 d'abr. 2019 a les 8:20:
The HTTP_X_CSRFTOKEN header does not match what is inside the csrftoken
cookie.

How can I examine the cookie? Set-Cookie is not displayed in the
Response header for Cross Domain requests.

I have already followed instructions found in:

https://stackoverflow.com/questions/39254562/csrf-with-django-reactredux-using-axios

Interestingly I found "X-CSRFTOKEN" translates to "HTTP_X_CSRFTOKEN" on
the server request header.

Thanks for any help.

Suresh

--
You received this message because you are subscribed to the Google Groups "Django users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to django-users+unsubscribe@googlegroups.com.
To post to this group, send email to django-users@googlegroups.com.
Visit this group at https://groups.google.com/group/django-users.
To view this discussion on the web visit https://groups.google.com/d/msgid/django-users/q9rj8u%24nlf%241%40blaine.gmane.org.
For more options, visit https://groups.google.com/d/optout.

--
You received this message because you are subscribed to the Google Groups "Django users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to django-users+unsubscribe@googlegroups.com.
To post to this group, send email to django-users@googlegroups.com.
Visit this group at https://groups.google.com/group/django-users.
To view this discussion on the web visit https://groups.google.com/d/msgid/django-users/CAK-JoTR5wGPvkbHkzcBZELrYL_nGCDbXN3C_SdGPHs4Ci-wOBA%40mail.gmail.com.
For more options, visit https://groups.google.com/d/optout.

No comments:

Post a Comment