[問題] Django Rest Framework CSRF
我想關閉某個post的 CSRF
http://www.django-rest-framework.org/api-guide/viewsets/#viewset
裡面提到
You can use any of the standard attributes such as permission_classes,
authentication_classes in order to control the API policy on the viewset.
stack overflow查到
http://goo.gl/k082op
所以我在我的view.py裡面加入
from rest_framework.authentication import
SessionAuthentication, BasicAuthentication,
class CsrfExemptSessionAuthentication(SessionAuthentication):
def enforce_csrf(self, request):
print('csrf exempt...') #從沒跑到這行
return
class ItemViewSet(viewsets.ModelViewSet):
queryset = Item.objects.all()
serializer_class = ItemSerializer
# 並且設定authentication_classes
authentication_classes = (CsrfExemptSessionAuthentication,
BasicAuthentication)
但是我仍然得到
Forbidden (CSRF cookie not set.)
請問我哪邊做錯了?
謝謝
--
※ 發信站: 批踢踢實業坊(ptt.cc), 來自: 204.96.168.3
※ 文章網址: https://www.ptt.cc/bbs/Python/M.1472769386.A.336.html
→
09/02 11:38, , 1F
09/02 11:38, 1F
→
09/02 11:38, , 2F
09/02 11:38, 2F
→
09/04 07:13, , 3F
09/04 07:13, 3F
→
10/06 23:57, , 4F
10/06 23:57, 4F