401ode / projects

An in-progress collection and presentation of RI technology projects.
Other
0 stars 0 forks source link

Prevent CSRF Cookie Issue when adding projects. #2

Open bmcguirk opened 8 years ago

bmcguirk commented 8 years ago

Make sure this error does not occur in prod:

In general, this can occur when there is a genuine Cross Site Request Forgery, or when Django's CSRF mechanism has not been used correctly. For POST forms, you need to ensure:
Your browser is accepting cookies.
The view function passes a request to the template's render method.
In the template, there is a {% csrf_token %} template tag inside each POST form that targets an internal URL.
If you are not using CsrfViewMiddleware, then you must use csrf_protect on any views that use the csrf_token template tag, as well as those that accept the POST data.
You're seeing the help section of this page because you have DEBUG = True in your Django settings file. Change that to False, and only the initial error message will be displayed.
You can customize this page using the CSRF_FAILURE_VIEW setting.
bmcguirk commented 8 years ago

Not happening in production on Cloud.gov. But it appears that this is actually a Python error.