From cd4ff9341e8a1bf9ca383b43facba573204f9fa1 Mon Sep 17 00:00:00 2001 From: Olivier Dony Date: Tue, 10 Jan 2017 17:02:39 +0100 Subject: [PATCH] [FIX] http: make error 400 slightly more user-friendly Users who get an error 400 due to an invalid CSRF token might be doing something legit. For example they may have opened the page with the HTTP form 2 hours before posting it, and let the CSRF token expire naturally (default lifetime is 1h). In this situation the "invalid CSRF token" message might be too cryptic for them to understand that they need to refresh the form and try again. Mentioning that their "Session expired" as well should sound more familiar and lead to the right reaction. --- openerp/http.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/openerp/http.py b/openerp/http.py index 5977b7a402d..a2364175bef 100644 --- a/openerp/http.py +++ b/openerp/http.py @@ -840,7 +840,7 @@ more details. passing the `csrf=False` parameter to the `route` decorator. """, request.httprequest.path) - raise werkzeug.exceptions.BadRequest('Invalid CSRF Token') + raise werkzeug.exceptions.BadRequest('Session expired (invalid CSRF token)') r = self._call_function(**self.params) if not r: