瀏覽代碼

Refs #28699 -- Clarified CSRF middleware ordering in relation to RemoteUserMiddleware.

Carlton Gibson 5 年之前
父節點
當前提交
9446950470
共有 1 個文件被更改,包括 4 次插入0 次删除
  1. 4 0
      docs/ref/middleware.txt

+ 4 - 0
docs/ref/middleware.txt

@@ -557,6 +557,10 @@ Here are some hints about the ordering of various Django middleware classes:
    Before any view middleware that assumes that CSRF attacks have been dealt
    with.
 
+   Before :class:`~django.contrib.auth.middleware.RemoteUserMiddleware`, or any
+   other authentication middleware that may perform a login, and hence rotate
+   the CSRF token, before calling down the middleware chain.
+
    After ``SessionMiddleware`` if you're using :setting:`CSRF_USE_SESSIONS`.
 
 #. :class:`~django.contrib.auth.middleware.AuthenticationMiddleware`