作者left (881 forever)
看板Python
标题[问题] Django {% csrf_token %}
时间Fri Aug 4 10:05:15 2017
{% csrf_token%}的问题
下面的code是照书做的(Django 架站的16堂课约莫在8-19至8-22页 )
环境 Django版本1.10, python 2.7
照书上写的我在<form></form>之间放进 {% csrf_token %},如下的posting.html
然後相对应的view function定义如下的 posting function
可是还是会出现下面的错误讯息
Help
Reason given for failure:
CSRF token missing or incorrect.
In general, this can occur when there is a genuine Cross Site Request Forgery, or when Django's CSRF mechanism has not been used correctly. For POST forms, you need to ensure:
Your browser is accepting cookies.
The view function passes a request to the template's render method.
In the template, there is a {% csrf_token %} template tag inside each POST form that targets an internal URL.
If you are not using CsrfViewMiddleware, then you must use csrf_protect on any views that use the csrf_tokentemplate tag, as well as those that accept the POST data.
The form has a valid CSRF token. After logging in in another browser tab or hitting the back button after a login, you may need to reload the page with the form, because the token is rotated after a login.
You're seeing the help section of this page because you have DEBUG = True in your Django settings file. Change that to False, and only the initial error message will be displayed.
You can customize this page using the CSRF_FAILURE_VIEW setting.
然後我照着上面的提示Django's CSRF mechanism以及render
把下面这几行用一行render处理
template = get_template('posting.html')
request_context = RequestContext(request)
request_context.push(locals())
html = template.render(request_context)
return HttpResponse(html)
也就是改成
return render(request, ‘posting.html’,locals())
结果错误讯息就不见了
我想要问各位大大,书上的写法有错吗?
如果有,要怎麽用RequestContext以及template.render()改到对?
如果没有,我是死在哪边? xd
def posting(request):
moods = models.Mood.objects.all()
message = "如要张贴讯息,则每一个栏位都要填..."
template = get_template('posting.html')
request_context = RequestContext(request)
request_context.push(locals())
html = template.render(request_context)
return HttpResponse(html)
posting.html:
{% extends "base.html" %}
{% block title %}我有话要说{% endblock %}
{% block content %}
<div class='container'>
{% if message %}
<div class='alert alert-warning'>{{message}}</div>
{% endif %}
<form name='my form' action='.' method='POST'>
{% csrf_token %}
现在的心情:<br/>
{% for m in moods %}
<input type='radio' name='mood' value='{{m.status}}'>{{m.status}}
{% endfor %}
<br/>
心情留言板:<br/>
<textarea name='user_post' rows=3 cols=70></textarea><br/>
<label for='user_id'>你的昵称:</label>
<input id='user_id' type='text' name='user_id'>
<label for='user_pass'>张贴/删除密码:</label>
<input id='user_pass' type='password' name='user_pass'>
<input type='submit' value='张贴'>
<input type='reset' value='清除重填'>
</form>
</div>
{% endblock %}
--
※ 发信站: 批踢踢实业坊(ptt.cc), 来自: 114.43.86.76
※ 文章网址: https://webptt.com/cn.aspx?n=bbs/Python/M.1501812320.A.517.html
※ 编辑: left (114.43.86.76), 08/04/2017 10:07:22
1F:→ uranusjr: 应该是书太旧了, 这个看起来像是 1.7 以前的写法 08/04 21:25
2F:→ uranusjr: 中间三行改 html = template.render(locals(), request) 08/04 21:26
3F:→ uranusjr: 这样就好了, 什麽 RequestContext 根本不用理它 08/04 21:26
4F:→ uranusjr: 详细原因和 Django 1.8 的 template refactoring 有关 08/04 21:28
5F:→ uranusjr: 另外嗯, 想学 Django 你有其他选择, 这本书可能不是最好 08/04 21:29