mirror of
https://github.com/django/django.git
synced 2025-10-24 06:06:09 +00:00
Fixed #26201 -- Documented the consequences of rotating the CSRF token on login.
This commit is contained in:
committed by
Tim Graham
parent
02ae5fd31a
commit
369fa471f4
@@ -78,6 +78,9 @@ CSRF_FAILURE_TEMPLATE = """
|
||||
<code>csrf_protect</code> on any views that use the <code>csrf_token</code>
|
||||
template tag, as well as those that accept the POST data.</li>
|
||||
|
||||
<li>The form has a valid CSRF token. After logging in in another browser
|
||||
tab or hitting the back button after a login, you may need to reload the
|
||||
page with the form, because the token is rotated after a login.</li>
|
||||
</ul>
|
||||
|
||||
<p>You're seeing the help section of this page because you have <code>DEBUG =
|
||||
|
||||
Reference in New Issue
Block a user