[FIX] http: make error 400 slightly more user-friendly

Users who get an error 400 due to an invalid CSRF
token might be doing something legit. For example
they may have opened the page with the HTTP form
2 hours before posting it, and let the CSRF token
expire naturally (default lifetime is 1h).

In this situation the "invalid CSRF token" message
might be too cryptic for them to understand that
they need to refresh the form and try again.

Mentioning that their "Session expired" as well
should sound more familiar and lead to the right
reaction.
This commit is contained in:
Olivier Dony
2017-01-10 17:09:03 +01:00
parent fc813847d8
commit cd4ff9341e
+1 -1
View File
@@ -840,7 +840,7 @@ more details.
passing the `csrf=False` parameter to the `route` decorator.
""", request.httprequest.path)
raise werkzeug.exceptions.BadRequest('Invalid CSRF Token')
raise werkzeug.exceptions.BadRequest('Session expired (invalid CSRF token)')
r = self._call_function(**self.params)
if not r: