Thursday, October 1, 2020

Retrieving csrftoken value with CSRF_USE_SESSIONS enabled


While working on turning on CSRF_USE_SESSIONS for a project, I noticed that the documentation recommends the following to retrieve the value:

{% csrf_token %}
const csrftoken = document.querySelector('[name=csrfmiddlewaretoken]').value;

I am wondering why not doing the following instead?

const csrftoken = "{{ csrf_token }}";

Is there some other security benefits I'm not thinking of?



No comments:

Post a Comment