python auth_error ai_generated true

BadRequest: The CSRF token is missing.

ID: python/flask-wtf-csrf-token-missing

Also available as: JSON · Markdown · 中文
80%Fix Rate
88%Confidence
0Evidence
2025-05-02First Seen

Version Compatibility

VersionStatusIntroducedDeprecatedNotes
1.2.x active — — —

Root Cause

POST/PUT/DELETE request lacks the `csrf_token` form field or `X-CSRFToken` header, or CSRFProtect is enabled without token in template.

generic

中文

POST/PUT/DELETE 请求缺少 `csrf_token` 表单字段或 `X-CSRFToken` 头,或启用了 CSRFProtect 但模板中未包含令牌。

Workarounds

  1. 95% success
    In template: `<form method="post">{{ csrf_token() }}...` or `<meta name="csrf-token" content="{{ csrf_token() }}">` and send as `X-CSRFToken` header from JS.
  2. 85% success
    For APIs using token auth, exempt only token-protected blueprints: `csrf.exempt(api_bp)`.

Dead Ends

Common approaches that don't work:

  1. 95% fail

    Removes protection; opens CSRF vulnerability.

  2. 90% fail

    Same as disabling; negates the extension.