mirror of
https://github.com/encode/django-rest-framework.git
synced 2025-01-24 08:14:16 +03:00
Modified documentation for CSRF as mentioned in #984
This commit is contained in:
parent
84b5f478f3
commit
8f2e71a67f
|
@ -23,7 +23,7 @@ To guard against these type of attacks, you need to do two things:
|
||||||
|
|
||||||
If you're using `SessionAuthentication` you'll need to include valid CSRF tokens for any `POST`, `PUT`, `PATCH` or `DELETE` operations.
|
If you're using `SessionAuthentication` you'll need to include valid CSRF tokens for any `POST`, `PUT`, `PATCH` or `DELETE` operations.
|
||||||
|
|
||||||
The Django documentation describes how to [include CSRF tokens in AJAX requests][csrf-ajax].
|
In order to make AJAX requests, you need to include CSRF token in the HTTP header, as [described in the Django documentation][csrf-ajax].
|
||||||
|
|
||||||
## CORS
|
## CORS
|
||||||
|
|
||||||
|
|
Loading…
Reference in New Issue
Block a user