validate_on_submit 与 CSRF 令牌
处理有效的提交,并阻止伪造请求
validate_on_submit 与 CSRF 令牌 是 CoddyKit 上的免费 Flask Academy 课时。 这是第 3 节课,共 4 节。 你可以在下方免费阅读本课时的完整内容 — 然后在浏览器中使用内置代码编辑器和全天候 AI 导师进行实践。 这是 Flask Academy 学习路径的一部分,你的进度在网页和 CoddyKit 应用中同步。 Flask Academy 课程共包含 4 节课。
本课时的部分内容尚未翻译,以英文显示。
The Golden Method
Flask-WTF gives you one method that checks everything at once. validate_on_submit is the heart of safely processing any form. 🔑
What It Actually Checks
validate_on_submit returns True only when the request is a POST and every validator passes. One call covers both conditions.
if form.validate_on_submit():
pass # safe to use the dataThe Standard View Pattern
This shape repeats in every Flask app: build the form, branch on validate_on_submit, then fall through to render the page.
form = LoginForm()
if form.validate_on_submit():
return redirect('/home')
return render_template('login.html', form=form)Submitted vs Valid
Do not confuse the two. is_submitted only checks the method, while validate_on_submit also confirms the data passed every rule.
form.is_submitted() # POST?
form.validate_on_submit() # POST and valid?Why CSRF Matters
A CSRF attack tricks a logged-in user into submitting a form they never meant to. Tokens prove the request came from your own page.
SECRET_KEY Is Required
CSRF tokens are signed, so Flask needs a SECRET_KEY. Without it, validation fails and Flask-WTF refuses to protect the form.
app.config['SECRET_KEY'] = 'change-me-in-production'The Token in the Page
That call to hidden_tag embeds the signed token as a hidden input. The browser sends it back with every submission.
{{ form.hidden_tag() }}Validation Compares Tokens
On submit, Flask-WTF compares the posted token against the session. A missing or stale token makes validate_on_submit return False.
if not form.validate_on_submit():
pass # bad token or failed ruleInspect Why It Failed
When validation fails, look at form.errors. It maps each field name to the list of messages explaining the problem.
if not form.validate_on_submit():
print(form.errors)Process Then Redirect
After a successful submit, finish with a redirect. That follows the PRG pattern and stops a refresh from posting twice.
if form.validate_on_submit():
save(form.data)
return redirect('/done')Never Disable CSRF Blindly
You can turn off CSRF for APIs, but never for browser forms. Keeping protection on is what makes Flask-WTF worth using.
Quick Check
When does form.validate_on_submit() return True?
Recap
You leaned on validate_on_submit for the method-plus-rules check, set a SECRET_KEY for signed CSRF tokens, and redirected after success. 🛡️
用 AI 导师学习 Python — 免费
在浏览器中编写并运行真实代码,获得全天候 AI 导师的即时帮助,并在网页或应用中继续学习。
- 课程
- 30
- 课程
- 120
常见问题解答
「validate_on_submit 与 CSRF 令牌」课时是免费的吗?
是的 — 「validate_on_submit 与 CSRF 令牌」的完整文本可在网页上免费阅读。要进行交互式练习(内置代码编辑器和全天候 AI 导师)并解锁 Flask Academy 课程的其余内容,请升级到 CoddyKit PRO。 Flask Academy 课程共包含 4 节课。
「validate_on_submit 与 CSRF 令牌」这节课中我会学到什么?
处理有效的提交,并阻止伪造请求 你通过在浏览器中直接运行的动手代码来练习 Flask Academy,全天候 AI 导师会在你学习这节课的过程中回答你的问题。
学习 Flask Academy 需要有经验吗?
无需任何先前经验。CoddyKit 上的 Flask Academy 课程适合初学者到高级学习者,你可以从这里开始或从头开始,按照自己的节奏学习。 这是第 3 节课,共 4 节。
「validate_on_submit 与 CSRF 令牌」课时需要多长时间?
大多数 CoddyKit 课程大约需要 5–10 分钟。每节课都很精短且互动,所以你能稳步进步,并在网页和应用中从离开的地方继续。
我能在这节 Flask Academy 课中编写并运行代码吗?
能。每节 Flask Academy 课都包含内置代码编辑器,你可以在浏览器中直接编写并运行真实代码,并获得即时 AI 反馈 — 无需本地设置。
此课程中的所有课时
- 定义 FlaskForm 类
- 渲染并提交表单
- validate_on_submit 与 CSRF 令牌
- 自定义验证器与字段错误