django 跨站请求伪造

def login(request):
	if request.method == 'POST':
		user = request.POST.get('username',None)
		pwd = request.POST.get('password',None)
		if user == 'alex' and pwd =='123':
			request.session['is_login'] = {'user':user}
			return redirect('/app02/index/')
		else:
			return render_to_response('/app02/login.html',{'msg':'用户名或密码错误'},context_instance=RequestContext(request))
	return render_to_response('app02/login.html',context_instance=RequestContext(request))


====================
login.html




    
    


    
{% csrf_token %}


你可能感兴趣的:(编程)