2017-02-15 161 views
1

我想使用.ajax发送一些数据到一个视图,但我得到的CSRF令牌丢失或不正确的错误。 我已将@ensure_csrf_cookie装饰器添加到呈现页面的视图中,以确保存在csrf cookie。 我使用Django 1.10.5和jQuery 3.1.1CSRF令牌丢失或不正确django

的Javascript

var csrftoken = Cookies.get('csrftoken'); 

function csrfSafeMethod(method) { 
    // these HTTP methods do not require CSRF protection 
    return (/^(GET|HEAD|OPTIONS|TRACE)$/.test(method)); 
} 
$.ajaxSetup({ 
    beforeSend: function(xhr, settings) { 
     if (!csrfSafeMethod(settings.type) && !this.crossDomain) { 
      xhr.setRequestHeader("X-CSRFToken", csrftoken); 
     } 
    } 
}); 

function updateWaypoints(){ 

    var routeArray =Array(), 
    routeArray = control.getWaypoints(); 
    routeArray.push({route_id:routeId}); 
    console.log(routeArray); 
    console.log(JSON.stringify(routeArray)); 
    var newData = JSON.stringify(routeArray); 

    $.ajax({ 
     type: 'POST', 
     url: '/routes/savemaproute/', 
     data: newData, 
    }); 
} 

视图功能是发送至:

@login_required 
def save_map_route(request): 
    if request.user in route.owner_user.all(): 
     if request.POST: 
      recieved_json_data = request.POST['data'] 
      route_id = request.POST['route_id'] 
      route = get_object_or_404(Route, pk=route_id) 
      route.map_waypoints = recieved_json_data 
      route.save() 
      return HttpResponseRedirect(reverse('route:details', args=(route_new.pk,))) 

urls.py

urlpatterns =[ 
    url(r'^$', views.index, name='index'), 
    url(r'^savemaproute/$', views.save_map_route, name='save_map_route'), 
    ] 

回答

0

您只是在发送到视图的数据中缺少csrftoken

var routeArray =Array(), 
    routeArray = control.getWaypoints(); 
    routeArray.push({route_id:routeId}); 
    console.log(routeArray); 
    console.log(JSON.stringify(routeArray)); 
    var newData = JSON.stringify(routeArray); 

您已经定义了csrftoken变量,但它不包含在您的newData中。

newData对象应该是这样的:

{ 
    // ... your key-value pairs 
    csrftoken: csrftoken 
} 
相关问题