pallets-eco/flask-wtf

Inconsistency with raising CSRFError

オープン

#381 opened on 2019/10/18

 (2 件のコメント) (0 件のリアクション) (0 人の担当者)Python (314 件のフォーク)github user discovery
csrfdocsgood first issue

Repository metrics

Stars
 (1,508 個のスター)
PR merge metrics
 (平均マージ 3h 45m) (30d で 3 merged PRs)

説明

The Flask-WTF docs state:

When CSRF validation fails, it will raise a CSRFError.

However, this appears to only be true, if this optional code has been used:

from flask_wtf.csrf import CSRFProtect
csrf = CSRFProtect(app)

When that code is not used, forms are created by subclassing FlaskForm, and CSRF validation fails, then validate_on_submit returns False instead of raising CSRFError.

It seems that ideally you would always raise CSRFError for consistency, but if you don't want to do that, then it would be helpful to update the docs.

コントリビューターガイド