Преглед изворни кода

Refs #28699 -- Clarified CSRF middleware ordering in relation to RemoteUserMiddleware.

Carlton Gibson пре 5 година
родитељ
комит
9446950470
1 измењених фајлова са 4 додато и 0 уклоњено
  1. 4 0
      docs/ref/middleware.txt

+ 4 - 0
docs/ref/middleware.txt

@@ -557,6 +557,10 @@ Here are some hints about the ordering of various Django middleware classes:
    Before any view middleware that assumes that CSRF attacks have been dealt
    with.
 
+   Before :class:`~django.contrib.auth.middleware.RemoteUserMiddleware`, or any
+   other authentication middleware that may perform a login, and hence rotate
+   the CSRF token, before calling down the middleware chain.
+
    After ``SessionMiddleware`` if you're using :setting:`CSRF_USE_SESSIONS`.
 
 #. :class:`~django.contrib.auth.middleware.AuthenticationMiddleware`