From 9b95fa7777c4b484f8053b87f48d65c853945f19 Mon Sep 17 00:00:00 2001 From: Bouke Haarsma Date: Sun, 3 Nov 2013 09:18:48 +0100 Subject: Fixed #21322 -- Error message when CSRF cookie is missing Thanks to Henrik Levkowetz and olau for their reports and initial patches. --- django/views/csrf.py | 16 +++++++++++++++- 1 file changed, 15 insertions(+), 1 deletion(-) (limited to 'django') diff --git a/django/views/csrf.py b/django/views/csrf.py index f942917e4b..b8de4851e7 100644 --- a/django/views/csrf.py +++ b/django/views/csrf.py @@ -41,6 +41,10 @@ CSRF_FAILURE_TEMPLATE = """

{{ no_referer1 }}

{{ no_referer2 }}

{% endif %} +{% if no_cookie %} +

{{ no_cookie1 }}

+

{{ no_cookie2 }}

+{% endif %} {% if DEBUG %}
@@ -95,7 +99,7 @@ def csrf_failure(request, reason=""): """ Default view used when request fails CSRF protection """ - from django.middleware.csrf import REASON_NO_REFERER + from django.middleware.csrf import REASON_NO_REFERER, REASON_NO_CSRF_COOKIE t = Template(CSRF_FAILURE_TEMPLATE) c = Context({ 'title': _("Forbidden"), @@ -111,6 +115,16 @@ def csrf_failure(request, reason=""): "If you have configured your browser to disable 'Referer' headers, " "please re-enable them, at least for this site, or for HTTPS " "connections, or for 'same-origin' requests."), + 'no_cookie': reason == REASON_NO_CSRF_COOKIE, + 'no_cookie1': _( + "You are seeing this message because this site requires a CSRF " + "cookie when submitting forms. This cookie is required for " + "security reasons, to ensure that your browser is not being " + "hijacked by third parties."), + 'no_cookie2': _( + "If you have configured your browser to disable cookies, please " + "re-enable them, at least for this site, or for 'same-origin' " + "requests."), 'DEBUG': settings.DEBUG, 'more': _("More information is available with DEBUG=True."), }) -- cgit v1.3