You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Django无CSRF Token实现CSRF及跨端协作下CSRF启用方案咨询

Hey folks, let's tackle these two Django CSRF questions one by one—they're common scenarios when working with frontend teams or exploring alternative protection methods:

1. 如何在Django框架中不使用CSRF Token实现CSRF防护?

CSRF tokens are the standard go-to, but there are alternative (though often supplementary) methods you can use:

  • Validate request origin via Referer/Origin headers
    Django's CSRF middleware already checks these headers by default, especially for HTTPS requests. You can configure CSRF_TRUSTED_ORIGINS in your settings.py to list trusted domains—if a request's Referer or Origin matches one of these, it passes validation. Note that some clients might strip the Referer header, so this isn't 100% foolproof, but it's a solid layer of defense.
  • Leverage SameSite cookie attributes
    Django sets the CSRF cookie with SameSite=Lax by default, which restricts the cookie to same-site requests (or safe cross-site GET requests). You can tighten this to SameSite=Strict in settings.py (CSRF_COOKIE_SAMESITE = 'Strict') to block even more cross-site requests, though this might break legitimate flows like cross-site form submissions (e.g., a user clicking a link from another site that posts to your app).
  • IP-based validation (not recommended for public systems)
    You could check if the request's IP is in a trusted list, but this is risky—IPs can be spoofed, and users might share IPs via proxies or corporate networks. Only use this for internal, closed systems where you have full control over client IPs.
2. 与无法提供代码的前端工程师协作,无法在Django模板中嵌入CSRF Token,如何启用CSRF功能?

If embedding the token in templates isn't an option, the key is to let the frontend fetch the token separately and include it in requests. Here's how:

  • Expose an API endpoint to return the CSRF token
    Create a simple view that returns the current user's CSRF token. This lets the frontend call the endpoint on page load to grab the token:

    from django.http import JsonResponse
    from django.middleware.csrf import get_token
    
    def csrf_token_view(request):
        return JsonResponse({'csrf_token': get_token(request)})
    

    Then map this view to a URL (e.g., /api/csrf-token/), and have the frontend fetch this endpoint, store the token, and add it as the X-CSRFToken header in all POST/PUT/DELETE requests.

  • Let the frontend read the CSRF token from cookies
    Django automatically sets a csrftoken cookie for authenticated users (and even for anonymous users if CSRF_COOKIE_HTTPONLY is False, which is the default). The frontend can extract this cookie value and attach it to the request header. Here's a quick JS snippet to do that:

    function getCsrfToken() {
        let token = null;
        const cookies = document.cookie.split(';');
        for (const cookie of cookies) {
            const [name, value] = cookie.trim().split('=');
            if (name === 'csrftoken') {
                token = decodeURIComponent(value);
                break;
            }
        }
        return token;
    }
    
    // Use in fetch/Axios:
    const csrfToken = getCsrfToken();
    fetch('/your-endpoint/', {
        method: 'POST',
        headers: {
            'X-CSRFToken': csrfToken,
            'Content-Type': 'application/json'
        },
        body: JSON.stringify(yourData)
    });
    

    Just make sure CSRF_COOKIE_HTTPONLY stays False in your settings—if it's set to True, frontend JS can't access the cookie, so you'll need to use the API endpoint method instead.

  • Confirm frontend request requirements
    Remind the frontend team that all state-modifying requests (POST, PUT, DELETE, etc.) must include the X-CSRFToken header with the valid token. Django's CSRF middleware will automatically validate this header against the stored cookie.

内容的提问来源于stack exchange,提问作者Guldam Kwak

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.07 20:43:14