[FIX] http: make error 400 slightly more user-friendly
Users who get an error 400 due to an invalid CSRF token might be doing something legit. For example they may have opened the page with the HTTP form 2 hours before posting it, and let the CSRF token expire naturally (default lifetime is 1h). In this situation the "invalid CSRF token" message might be too cryptic for them to understand that they need to refresh the form and try again. Mentioning that their "Session expired" as well should sound more familiar and lead to the right reaction.
This commit is contained in:
+1
-1
@@ -840,7 +840,7 @@ more details.
|
||||
passing the `csrf=False` parameter to the `route` decorator.
|
||||
""", request.httprequest.path)
|
||||
|
||||
raise werkzeug.exceptions.BadRequest('Invalid CSRF Token')
|
||||
raise werkzeug.exceptions.BadRequest('Session expired (invalid CSRF token)')
|
||||
|
||||
r = self._call_function(**self.params)
|
||||
if not r:
|
||||
|
||||
Reference in New Issue
Block a user