feat(auth): graceful CSRF-failure retry on login - #3174
Open
FrankApiyo wants to merge 1 commit into
Open
Conversation
A CSRF failure on the login page is almost always a stale/rotated token (old tab, back button, cookie rotation), not an attack — but Django's default response is a dead-end 403 that strands the user. Add a CSRF_FAILURE_VIEW that sends a failed login POST back to a fresh login (new token) so the user can simply retry, preserving a safe ?next= so a brokered OIDC flow continues. Non-login CSRF failures keep the default 403, so genuine cross-site API POSTs are not masked.
2 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Changes / Features implemented
A login POST that fails CSRF validation (stale or rotated token — e.g. a login tab left open across a deploy) now redirects back to a fresh login page with the safe
nextpreserved, instead of dead-ending on Django's 403 page.Steps taken to verify this change does what is intended
nextsafety (unsafe values dropped), non-login paths keep the default 403Side effects of implementing this change
Before submitting this PR for review, please make sure you have: