Merge pull request #1896 from dbrgn/csrf_response

Changed return status for CSRF failures to HTTP 403
This commit is contained in:
Tom Christie 2014-09-23 14:30:35 +01:00
commit aa84432f9b

View File

@ -129,7 +129,7 @@ class SessionAuthentication(BaseAuthentication):
reason = CSRFCheck().process_view(request, None, (), {})
if reason:
# CSRF failed, bail with explicit error message
raise exceptions.AuthenticationFailed('CSRF Failed: %s' % reason)
raise exceptions.PermissionDenied('CSRF Failed: %s' % reason)
class TokenAuthentication(BaseAuthentication):