CSRF Security का Overview
<form method="post">
{% csrf_token %}
<!-- form fields -->
</form>
CSRF Protection क्या रोकता है
Protection के बिना, एक malicious website एक hidden form embed कर सकती है जो victim की existing login session उपयोग करके आपकी site पर submit होता है, वे actions perform करते हुए जिनसे victim ने कभी agree नहीं किया।
Django का CSRF token हर form submission को उस page से tie करता है जिसने इसे legitimately render किया।
उदाहरण: What CSRF Protection Prevents
Without protection, a malicious website could embed a hidden form that submits to your site using the victim's existing login session, performing actions the victim never agreed to. Django's CSRF token ties every form submission to the page that legitimately rendered it.
<!-- templates/donate.html -->
<form method="post">
{% csrf_token %}
<label for="amount">Amount</label>
<input type="number" id="amount" name="amount">
<button type="submit">Donate</button>
</form>
{# Django-only code -- models.py/views.py/urls.py/settings.py
snippets, or template markup using Django template tags/variables
-- can't run standalone via Judge0 or the browser preview, since
it needs a real Django project. Only this course's pure-Python
examples (example_lang == 'python', no Django imports) are
actually runnable, so those still get the button below. #}
Middleware इसे कैसे जांचता है
django.middleware.csrf.CsrfViewMiddleware settings.py में default रूप से enabled है। हर POST request पर, यह form में submitted token को user की session/cookie में stored token से compare करता है, अगर वे match न करें तो request को 403 के साथ reject करते हुए।
MIDDLEWARE में रहना चाहिए।उदाहरण: How the Middleware Checks It
django.middleware.csrf.CsrfViewMiddleware is enabled by default in settings.py. On every POST request, it compares the token submitted in the form against the one stored in the user's session/cookie, rejecting the request with a 403 if they don't match.
# settings.py -- CSRF middleware is on by default
MIDDLEWARE = [
'django.middleware.security.SecurityMiddleware',
'django.contrib.sessions.middleware.SessionMiddleware',
'django.middleware.csrf.CsrfViewMiddleware',
'django.contrib.auth.middleware.AuthenticationMiddleware',
]
{# Django-only code -- models.py/views.py/urls.py/settings.py
snippets, or template markup using Django template tags/variables
-- can't run standalone via Judge0 or the browser preview, since
it needs a real Django project. Only this course's pure-Python
examples (example_lang == 'python', no Django imports) are
actually runnable, so those still get the button below. #}
JavaScript से Token भेजना
एक plain HTML form के बजाय fetch() या AJAX के through एक POST request submit करते समय, CSRF token को cookie से पढ़ा जाना चाहिए और एक request header के रूप में भेजा जाना चाहिए।
उदाहरण: Sending the Token from JavaScript
When submitting a POST request via fetch() or AJAX instead of a plain HTML form, the CSRF token must be read from the cookie and sent as a request header.
// Read the csrftoken cookie Django sets automatically
function getCookie(name) {
const match = document.cookie.match('(^|;)\\s*' + name + '\\s*=\\s*([^;]+)');
return match ? match.pop() : '';
}
fetch('/donate/', {
method: 'POST',
headers: { 'X-CSRFToken': getCookie('csrftoken') },
body: new URLSearchParams({ amount: 10 }),
});
{# Django-only code -- models.py/views.py/urls.py/settings.py
snippets, or template markup using Django template tags/variables
-- can't run standalone via Judge0 or the browser preview, since
it needs a real Django project. Only this course's pure-Python
examples (example_lang == 'python', no Django imports) are
actually runnable, so those still get the button below. #}
- यह समझने के बजाय कि यह क्यों required है, एक confusing 403 error fix करने के लिए form से
{% csrf_token %}हटाना। - सिर्फ एक error गायब करने के लिए एक view पर
@csrf_exemptउपयोग करना, इसे cross-site attacks के लिए खोलते हुए। - यह भूल जाना कि AJAX POST requests को भी CSRF token एक header के रूप में भेजना होता है, सिर्फ HTML forms में नहीं।
- CSRF (Cross-Site Request Forgery) एक logged-in user के browser को ऐसा request submit करने के लिए trick करता है जो उसने करने का इरादा नहीं रखा था।
- Django का CsrfViewMiddleware हर unsafe request (POST, PUT, DELETE) पर एक valid token जांचता है।
- POST से submit होने वाला हर form
<form>tag के अंदर{% csrf_token %}include करना चाहिए। - Token prove करता है कि request असल में आपकी site के अपने page से आया, किसी attacker के page से नहीं।
Chapter Quiz — Complete all 9 topics to unlock
0/9 topics done
Complete these topics first: