帮助
失败原因:
Origin checking failed - https://praktikum6.jhoncena.repl.co does not match any trusted origins.
通常情况下,这会在发生真正的跨站点请求伪造或Django的CSRF机制未正确使用时发生。对于POST表单,您需要确保:
Your browser is accepting cookies.
The view function passes a request to the template’s render method.
In the template, there is a {% csrf_token %} template tag inside each POST form that targets an internal URL.
If you are not using CsrfViewMiddleware, then you must use csrf_protect on any views that use the csrf_token template tag, as well as those that accept the POST data.
The form has a valid CSRF token. After logging in in another browser tab or hitting the back button after a login, you may need to reload the page with the form, because the token is rotated after a login.
因为您在Django设置文件中将DEBUG设置为True,所以您正在查看此页面的帮助部分。将其更改为False,只会显示最初的错误消息。
您可以使用CSRF_FAILURE_VIEW设置自定义此页面。
ALLOWED_HOSTS
设置从环境变量中获取值,那么将CSRF_TRUSTED_ORIGINS
设置为相同的值是否有任何不合适之处?例如os.getenv('ALLOWED_HOSTS').split(',')
? - pspahnSECURE_PROXY_SSL_HEADER
) - Michael Herrmann