为什么在SetCookie头字段中找不到CSRF令牌?

2024-05-14 00:26:29 发布

您现在位置:Python中文网/ 问答频道 /正文

我有一个Django Rest framework APIView类,如下所示:

class HelloView(APIView):

    def get(self, request):
        clients = client.objects.all()
        serializer = ClientSerializerAPIView(clients, many=True) 
        return Response(serializer.data)
    def post(self, request):
        serializer = ClientSerializerAPIView(data=request.data)
        if serializer.is_valid():
            serializer.save()
            return Response(serializer.data, status=status.HTTP_201_CREATED)
        return Response(serializer.errors, status=status.HTTP_404_NOT_FOUND)

当我通过postman发送get请求时,postman的cookie部分中有一个csrf令牌,但问题是在接收到的头文件中没有设置cookie字段,我可以从中gram csrftoken。在

enter image description here

enter image description here


Tags: selfhttpdatagetreturncookieresponserequest