Welcome to OGeek Q&A Community for programmer and developer-Open, Learning and Share
Welcome To Ask or Share your Answers For Others

Categories

0 votes
272 views
in Technique[技术] by (71.8m points)

Is it secure to create API in Django without Rest Framework?

I've created an app in my Django project which works the same as API.
But for post requests, logins I'm doing something like this.

request "GET"(URL: example.com/api/get) this returns a csrftoken which is then used by my applications as a cookie.

request "POST"(URL: example.com/api/login), Here the frontend application logs in the user. The csrftoken from example.com/api/get is used in cookies and the same is used as csrfmiddlewaretoken in post data.

My question here is, it is secure to create an API like this and use it instead of Django RestFramework.
Any suggestion will be appreciated.
THANK YOU


与恶龙缠斗过久,自身亦成为恶龙;凝视深渊过久,深渊将回以凝视…
Welcome To Ask or Share your Answers For Others

1 Reply

0 votes
by (71.8m points)
等待大神答复

与恶龙缠斗过久,自身亦成为恶龙;凝视深渊过久,深渊将回以凝视…
OGeek|极客中国-欢迎来到极客的世界,一个免费开放的程序员编程交流平台!开放,进步,分享!让技术改变生活,让极客改变未来! Welcome to OGeek Q&A Community for programmer and developer-Open, Learning and Share
Click Here to Ask a Question

...