comments ๋“ฑ๋กํผ ๋งŒ๋“œ๋Š”๋ฐ CSRF์—๋Ÿฌ๊ฐ€ ๋œจ๋Š”๋ฐ ํ•ด๊ฒฐ๋ฐฉ๋ฒ•์„ ๋ชป์ฐพ๊ฒ ์Šต๋‹ˆ๋‹ค.

669 views
Skip to first unread message

donghuna

unread,
Aug 19, 2012, 1:16:30โ€ฏPM8/19/12
to djan...@googlegroups.com
1 {% load comments %} 2 <form method="POST" action="{% comment_form_target %}" class="comment_form"> 3 {% csrf_token %} 4 <dl> 5 <dt class="comment_user"> 6 {{ user.username }} 7 </dt> 8 <dd class="comment_content"> 9 {{ form.comment }} 10 <input type="submit" class="eng button" value="Comment"/> 11 </dd> 12 </dl> 13 {{ form.content_type }} 14 {{ form.object_pk }} 15 {{ form.timestamp }} 16 {{ form.security_hash }} 17 <input type="hidden" name="next" value="{{ request.get_full_path }}"/> 18 </form>

csrf_token ์ ์–ด๋†“์•˜๋Š”๋ฐ๋„ ๊ณ„์† ์ด๋Ÿฐ ์˜ค๋ฅ˜๊ฐ€ ๋ฐœ์ƒํ•ฉ๋‹ˆ๋‹ค.ใ… 
์–ด๋–ป๊ฒŒ ํ•ด์•ผ๋ ๊นŒ์š” ใ… ใ… 

์ด์ˆœ์—ฐ

unread,
Aug 19, 2012, 1:24:53โ€ฏPM8/19/12
to djan...@googlegroups.com
์‹ค์ œ ๋ธŒ๋ผ์šฐ์ €์—์„œ ๊ฐ’์ด ํ† ํฐ์ด ์ถœ๋ ฅ๋˜๋Š”์ง€ ํ™•์ธํ•˜์…จ๋Š”์ง€์š”?

2012๋…„ 8์›” 20์ผ ์˜ค์ „ 2:16, donghuna <dong...@gmail.com>๋‹˜์˜ ๋ง:

--
Google ๊ทธ๋ฃน์Šค 'Django-ko' ๊ทธ๋ฃน์— ๊ฐ€์ž…ํ–ˆ์œผ๋ฏ€๋กœ ๋ณธ ๋ฉ”์ผ์ด ์ „์†ก๋˜์—ˆ์Šต๋‹ˆ๋‹ค.
์›น์—์„œ ์ด ํ† ๋ก ์„ ๋ณด๋ ค๋ฉด https://groups.google.com/d/msg/django-ko/-/0tOpErF5dvAJ์„(๋ฅผ) ๋ฐฉ๋ฌธํ•˜์„ธ์š”.
์ด ๊ทธ๋ฃน์— ๊ฒŒ์‹œํ•˜๋ ค๋ฉด djan...@googlegroups.com(์œผ)๋กœ ์ด๋ฉ”์ผ์„ ๋ณด๋‚ด์„ธ์š”.
๊ทธ๋ฃน์—์„œ ํƒˆํ‡ดํ•˜๋ ค๋ฉด django-ko+...@googlegroups.com๋กœ ์ด๋ฉ”์ผ์„ ๋ณด๋‚ด์ฃผ์„ธ์š”.
๋” ๋งŽ์€ ์˜ต์…˜์„ ๋ณด๋ ค๋ฉด http://groups.google.com/group/django-ko?hl=ko์—์„œ ๊ทธ๋ฃน์„ ๋ฐฉ๋ฌธํ•˜์„ธ์š”.



--


-------------------------

์œ ํ•˜์†Œํ”„ํŠธ ์ด ์ˆœ์—ฐ
010-4278-1346



donghuna

unread,
Aug 19, 2012, 1:46:14โ€ฏPM8/19/12
to djan...@googlegroups.com
์ œ๊ฐ€ ์›น๊ณต๋ถ€ํ•œ์ง€๊ฐ€ ์–ผ๋งˆ ์•ˆ๋˜์–ด์„œ ๋ธŒ๋ผ์šฐ์ €์—์„œ ํ† ํฐ์ด ์ถœ๋ ฅ๋˜๋Š”์ง€์˜ ์—ฌ๋ถ€๋ฅผ ํ™•์ธํ• ์ค„ ๋ชจ๋ฆ…๋‹ˆ๋‹ค. ใ… ใ… 
๋‹จ์ˆœํžˆ์ด๋Ÿฐ ์—๋Ÿฌ๊ฐ€ ๋ณด์•ˆ์ƒ ์ƒ๊ธฐ๋Š” ๋ฌธ์ œ์—ฌ์„œ post ํ•˜๊ธฐ์ „์— <form>๋ฐ”๋กœ ์•„๋ž˜์— {% csrf_token %}์„ ์ ์–ด์ฃผ๋˜์ง€,
view์ชฝ์—์„œ @csrf_exempt๋ฅผ ๋ฉ”์†Œ๋“œ ์œ„์— ์ ์–ด์ฃผ๋Š”๊ฒƒ์œผ๋กœ ์•Œ๊ณ  ์žˆ์—ˆ๊ฑฐ๋“ ์š”..

2012๋…„ 8์›” 20์ผ ์›”์š”์ผ ์˜ค์ „ 2์‹œ 24๋ถ„ 53์ดˆ UTC+9, ์ˆœ์—ฐ ์ด ๋‹˜์˜ ๋ง:

์ด์ˆœ์—ฐ

unread,
Aug 19, 2012, 1:49:50โ€ฏPM8/19/12
to djan...@googlegroups.com
๋„ค. ์—๋Ÿฌ ์ถœ๋ ฅ๋‚ด์šฉ์„ ๋ณผ ์ˆ˜ ์žˆ์„๊นŒ์š”?

2012๋…„ 8์›” 20์ผ ์˜ค์ „ 2:46, donghuna <dong...@gmail.com>๋‹˜์˜ ๋ง:
์›น์—์„œ ์ด ํ† ๋ก ์„ ๋ณด๋ ค๋ฉด https://groups.google.com/d/msg/django-ko/-/4zcUSpn75pYJ์„(๋ฅผ) ๋ฐฉ๋ฌธํ•˜์„ธ์š”.

์ด ๊ทธ๋ฃน์— ๊ฒŒ์‹œํ•˜๋ ค๋ฉด djan...@googlegroups.com(์œผ)๋กœ ์ด๋ฉ”์ผ์„ ๋ณด๋‚ด์„ธ์š”.
๊ทธ๋ฃน์—์„œ ํƒˆํ‡ดํ•˜๋ ค๋ฉด django-ko+...@googlegroups.com๋กœ ์ด๋ฉ”์ผ์„ ๋ณด๋‚ด์ฃผ์„ธ์š”.
๋” ๋งŽ์€ ์˜ต์…˜์„ ๋ณด๋ ค๋ฉด http://groups.google.com/group/django-ko?hl=ko์—์„œ ๊ทธ๋ฃน์„ ๋ฐฉ๋ฌธํ•˜์„ธ์š”.

donghuna

unread,
Aug 19, 2012, 1:52:55โ€ฏPM8/19/12
to djan...@googlegroups.com

Forbiddenย (403)

CSRF verification failed. Request aborted.

Help

Reason given for failure:

    CSRF token missing or incorrect.
    

In general, this can occur when there is a genuine Cross Site Request Forgery, or whenย Django's CSRF mechanismย has not been used correctly. For POST forms, you need to ensure:

  • Your browser is accepting cookies.
  • The view function usesย RequestContextย for the template, instead ofย Context.
  • In the template, there is aย {% csrf_token %}ย template tag inside each POST form that targets an internal URL.
  • If you are not usingย CsrfViewMiddleware, then you must useย csrf_protectย on any views that use theย csrf_tokenย template tag, as well as those that accept the POST data.

You're seeing the help section of this page because you haveย DEBUG = Trueย in your Django settings file. Change that toย False, and only the initial error message will be displayed.

You can customize this page using the CSRF_FAILURE_VIEW setting.

์ด์ˆœ์—ฐ

unread,
Aug 19, 2012, 1:58:24โ€ฏPM8/19/12
to djan...@googlegroups.com
๋„ค..
๋ธŒ๋ผ์šฐ์ €์—์„œ ํฌ์ŠคํŒ…ํ•˜๊ธฐ์ „ '์†Œ์Šค๋ณด๊ธฐ'๋ฅผ ์‹คํ–‰ํ•˜์—ฌ form์— ํ† ํฐ์ด ์ •์ƒ์ ์œผ๋กœ ์ถœ๋ ฅ๋˜์–ด ์žˆ๋Š”์ง€ ํ™•์ธํ•  ํ•„์š”๊ฐ€ ์žˆ๋Š” ๊ฒƒ ๊ฐ™์Šต๋‹ˆ๋‹ค.

๊ทธ๋ฆฌ๊ณ  settings.py์˜ ๋ฏธ๋“ค์›จ์–ด ํด๋ž˜์Šค์— ์•„๋ž˜์™€ ๊ฐ™์ดย CsrfViewMiddleware๊ฐ€ ๋“ค์–ด๊ฐ€ ์žˆ๋Š”์ง€๋„์š”.

MIDDLEWARE_CLASSES = (

ย  ย  .....

ย  ย  'django.middleware.csrf.CsrfViewMiddleware',

ย  ย  ...

}



2012/8/20 donghuna <dong...@gmail.com>

--
Google ๊ทธ๋ฃน์Šค 'Django-ko' ๊ทธ๋ฃน์— ๊ฐ€์ž…ํ–ˆ์œผ๋ฏ€๋กœ ๋ณธ ๋ฉ”์ผ์ด ์ „์†ก๋˜์—ˆ์Šต๋‹ˆ๋‹ค.
์›น์—์„œ ์ด ํ† ๋ก ์„ ๋ณด๋ ค๋ฉด https://groups.google.com/d/msg/django-ko/-/mKbLURqPjWMJ์„(๋ฅผ) ๋ฐฉ๋ฌธํ•˜์„ธ์š”.

์ด ๊ทธ๋ฃน์— ๊ฒŒ์‹œํ•˜๋ ค๋ฉด djan...@googlegroups.com(์œผ)๋กœ ์ด๋ฉ”์ผ์„ ๋ณด๋‚ด์„ธ์š”.
๊ทธ๋ฃน์—์„œ ํƒˆํ‡ดํ•˜๋ ค๋ฉด django-ko+...@googlegroups.com๋กœ ์ด๋ฉ”์ผ์„ ๋ณด๋‚ด์ฃผ์„ธ์š”.
๋” ๋งŽ์€ ์˜ต์…˜์„ ๋ณด๋ ค๋ฉด http://groups.google.com/group/django-ko?hl=ko์—์„œ ๊ทธ๋ฃน์„ ๋ฐฉ๋ฌธํ•˜์„ธ์š”.

donghuna

unread,
Aug 19, 2012, 2:12:52โ€ฏPM8/19/12
to djan...@googlegroups.com
์†Œ์Šค๋ณด๊ธฐ๋กœ ๋ณด๋‹ˆ๊นŒ ๋งˆ์ง€๋ง‰์— request.get_full_path ๋ณ€์ˆ˜๊ฐ’์ด ์•ˆ๋“ค์–ด์™”๋„ค์š”..
๋‹ต๋ณ€ ์ •๋ง ๊ฐ์‚ฌํ•ฉ๋‹ˆ๋‹ค!! ^^



2012๋…„ 8์›” 20์ผ ์›”์š”์ผ ์˜ค์ „ 2์‹œ 58๋ถ„ 24์ดˆ UTC+9, ์ˆœ์—ฐ ์ด ๋‹˜์˜ ๋ง:

donghuna

unread,
Aug 19, 2012, 7:52:59โ€ฏPM8/19/12
to djan...@googlegroups.com
์—๋Ÿฌ๋Š” ๊ณ„์† ๋œจ๋„ค์š” ใ… ใ… ใ… 

2012๋…„ 8์›” 20์ผ ์›”์š”์ผ ์˜ค์ „ 3์‹œ 12๋ถ„ 52์ดˆ UTC+9, donghuna ๋‹˜์˜ ๋ง:
Reply all
Reply to author
Forward
0 new messages