python
auth_error
ai_generated
true
BadRequest: The CSRF token is missing.
ID: python/flask-wtf-csrf-token-missing
80%Fix Rate
88%Confidence
0Evidence
2025-05-02First Seen
Version Compatibility
| Version | Status | Introduced | Deprecated | Notes |
|---|---|---|---|---|
| 1.2.x | active | — | — | — |
Root Cause
POST/PUT/DELETE request lacks the `csrf_token` form field or `X-CSRFToken` header, or CSRFProtect is enabled without token in template.
generic中文
POST/PUT/DELETE 请求缺少 `csrf_token` 表单字段或 `X-CSRFToken` 头,或启用了 CSRFProtect 但模板中未包含令牌。
Workarounds
-
95% success
In template: `<form method="post">{{ csrf_token() }}...` or `<meta name="csrf-token" content="{{ csrf_token() }}">` and send as `X-CSRFToken` header from JS. -
85% success
For APIs using token auth, exempt only token-protected blueprints: `csrf.exempt(api_bp)`.
Dead Ends
Common approaches that don't work:
-
95% fail
Removes protection; opens CSRF vulnerability.
-
90% fail
Same as disabling; negates the extension.