开启csrf保护有两种方法,我们用第二种在Ajax添加请求头:
Ajax添加请求头:
headers:{'X-CSRFToken':getCookie('csrf_token')},
后台在创建app的函数中写入:
from flask_wtf import CSRFProtect
from flask_wtf.csrf import generate_csrf
CSRFProtect(app)
@app.after_request
def after_request(response):
response.set_cookie("csrf_token",generate_csrf())
return response