Skip to Content
Django 3 Web Development Cookbook - Fourth Edition
book

Django 3 Web Development Cookbook - Fourth Edition

by Aidas Bendoraitis, Jake Kronika
March 2020
Intermediate to advanced
608 pages
17h 17m
English
Packt Publishing
Content preview from Django 3 Web Development Cookbook - Fourth Edition

How it works...

Django uses a hidden field approach to prevent CSRF attacks. A token is generated on the server, based on a combination of request-specific and randomized information. Through CsrfViewMiddleware, this token is automatically made available via the request context. While it is not recommended to disable this middleware, it is possible to mark individual views to get the same behavior by applying the @csrf_protect decorator:

from django.views.decorators.csrf import csrf_protect@csrf_protectdef my_protected_form_view():    # …

Similarly, we can exclude individual views from CSRF checks, even when the middleware is enabled, by using the @csrf_exempt decorator:

from django.views.decorators.csrf import csrf_exempt@csrf_exemptdef my_unsecured_form_view(): ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Start your free trial

You might also like

Django 2 Web Development Cookbook - Third Edition

Django 2 Web Development Cookbook - Third Edition

Jake Kronika, Aidas Bendoraitis

Publisher Resources

ISBN: 9781838987428Supplemental Content