We are a small, intelligent App development studio. We love "Building Amazing Apps", solving problems and cultivating strong relationships with our clients.
Reactions
shabda
8th June, 2011
RT@tuxcanfly: http://agiliq.com/blog/2011/06/django-csrf-error-on-non-existent-urls/ Long time, no blog post.
tuxcanfly
8th June, 2011
http://agiliq.com/blog/2011/06/django-csrf-error-on-non-existent-urls/ Long time, no blog post.
Recent Articles
- Common testing scenarios for Django app.
- Logging in Django
- Serving static files in Django
- Two Scoops of Django: Review
- Introduction to Python Workshop on February 15th, 2013
- Easy client side form validations for Django: Django Parsley
- MoreApps - Android Library Project: Open Sourced
- Tutorial: Building a Chrome app
- Password Generator App: Open Sourced
- Todo List App: Open Sourced
About Agiliq
Topics
Archives
- April 2013
- March 2013
- February 2013
- January 2013
- November 2012
- October 2012
- September 2012
- July 2012
- June 2012
- May 2012
- April 2012
- March 2012
- February 2012
- January 2012
- December 2011
- October 2011
- September 2011
- July 2011
- June 2011
- April 2011
- February 2011
- January 2011
- December 2010
- November 2010
- October 2010
- September 2010
- June 2010
- April 2010
- March 2010
- January 2010
- December 2009
- November 2009
- October 2009
- September 2009
- August 2009
- July 2009
- June 2009
- April 2009
- March 2009
- February 2009
- November 2008
- October 2008
- June 2008
- May 2008
- April 2008
Django: csrf error on non-existent urls
By : Javed Khan
While testing out a API from another django site, I came across a seemingly common error.
403 Forbidden CSRF verification failed. Request aborted. Help Reason given for failure: No CSRF or session cookie.Posting the data to the api endpoint returned
403 Forbiddenwith the standard csrf failure error page. I cross checked that the view wascsrf_exemptedand thatCsrfViewMiddlewarewas not enabled. The view had some other unrelated decorators which I guessed could be the cause of the problem. According to this bug, not all decorators play nice with thecsrf_exemptdecorator. Even with that fixed, there was no luck.Well, turns out that I was posting the data to a non-existent URL (/facepalm) and django was catching the csrf part earlier than the not found part. For more discussion about this topic look at HTTP POST sent from app to Django Server returns 403 Forbidden
Lessons of the day:
Can we help you build amazing apps? Contact us today.