# BadRequest: CSRF 令牌缺失。

- **ID:** `python/flask-wtf-csrf-token-missing`
- **领域:** python
- **类别:** auth_error
- **验证级别:** ai_generated
- **修复率:** 80%

## 根因

POST/PUT/DELETE 请求缺少 `csrf_token` 表单字段或 `X-CSRFToken` 头，或启用了 CSRFProtect 但模板中未包含令牌。

## 版本兼容性

| 版本 | 状态 | 引入 | 弃用 |
|------|------|------|------|
| 1.2.x | active | — | — |

## 解决方案

1. **** (95% 成功率)
   ```
   In template: `<form method="post">{{ csrf_token() }}...` or `<meta name="csrf-token" content="{{ csrf_token() }}">` and send as `X-CSRFToken` header from JS.
   ```
2. **** (85% 成功率)
   ```
   For APIs using token auth, exempt only token-protected blueprints: `csrf.exempt(api_bp)`.
   ```

## 无效尝试

- **** — Removes protection; opens CSRF vulnerability. (95% 失败率)
- **** — Same as disabling; negates the extension. (90% 失败率)
