【问题标题】:CSRF verification failed. Request aborted when updating a formCSRF 验证失败。更新表单时请求中止
【发布时间】:2014-12-14 14:19:27
【问题描述】:

我有以下模板

{% block content %}
    <form enctype="multipart/form-data" action="" method="post">{% csrf_token %}
    {% for field in form %}
        {{ field.label_tag }} {{ field }}
    {% endfor %}
    <input type="submit" value="Submit">
    </form>
{% endblock %}

这是使用此模型构建的

class TProfiles(models.Model):
    id = models.IntegerField(primary_key=True)  # AutoField?
    first_name = models.CharField(max_length=45, blank=True)
    surname = models.CharField(max_length=45, blank=True)
    email = models.CharField(max_length=45, blank=True)

class Meta:
    managed = False
    db_table = 'profiles'

class TProfilesForm(ModelForm):
    class Meta:
        model = TProfiles
        fields = ['first_name', 'surname', 'email']

哪些被传递给视图

def register(request):
    form = TProfilesForm()

    if request.method == 'POST':
        form = TProfilesForm(request.POST)
        if form.is_valid():
            form.save()

    return render_to_response("register.html", {
        "form": form,
    })

但是,我在尝试保存字段时不断收到错误消息。 CSRF 错误似乎有多种形式......

编辑 - 错误消息

Forbidden (403)
CSRF verification failed. Request aborted.
Help
Reason given for failure:
    CSRF token missing or incorrect.

In general, this can occur when there is a genuine Cross Site Request Forgery, or when Django's   CSRF mechanism has not been used correctly. For POST forms, you need to ensure:
Your browser is accepting cookies.
The view function uses RequestContext for the template, instead of Context.
In the template, there is a {% csrf_token %} template tag inside each POST form that targets an internal URL.
If you are not using CsrfViewMiddleware, then you must use csrf_protect on any views that use the csrf_token template tag, as well as those that accept the POST data.
You're seeing the help section of this page because you have DEBUG = True in your Django settings file. Change that to False, and only the initial error message will be displayed.
You can customize this page using the CSRF_FAILURE_VIEW setting.

【问题讨论】:

  • 你能发布回溯吗?
  • 它们可能确实有多种风格,但您在尝试此操作时看到(但未发布)的错误消息明确解决了您的问题;你没有使用 RequestContext。
  • 抱歉,请参阅我的编辑。这是我可以看到的错误页面上的所有内容。

标签: django django-models django-forms django-templates django-views


【解决方案1】:

或者直接使用 render 代替 render_to_response:

return render(request,"register.html", {"form": form,})

进口:

from django.shortcuts import render

【讨论】:

    【解决方案2】:

    答案似乎是在return语句中添加RequestContext(request)。所以我的代码看起来像:

    def register(request):
        form = TProfilesForm()
    
        if request.method == 'POST':
            form = TProfilesForm(request.POST)
            if form.is_valid():
                form.save()
    
    
        return render_to_response("register.html", {
            "form": form,
        }, RequestContext(request))  
    

    找到答案here

    【讨论】:

      猜你喜欢
      • 1970-01-01
      • 2012-05-10
      • 2017-06-17
      • 2012-12-07
      • 2015-03-08
      • 1970-01-01
      • 2016-08-27
      相关资源
      最近更新 更多