# Forwarded headers CSRF hints

**URL:** <https://forum.djangoproject.com/t/forwarded-headers-csrf-hints/28616>\
**Category:** Django Internals\
**Created:** [March 2, 2024, 3:49am UTC](https://forum.djangoproject.com/t/forwarded-headers-csrf-hints/28616 "2024-03-02T03:49:48Z")\
**Posts on this page:** 1\
**Showing post:** 3

<div class="post-metadata">

**Author:** ![CodenameTim](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/codenametim/32/31507_2.png) [@CodenameTim](https://forum.djangoproject.com/u/CodenameTim)\
**Post date:** [March 2, 2024, 9:47am UTC](https://forum.djangoproject.com/t/forwarded-headers-csrf-hints/28616/3 "2024-03-02T09:47:39Z")

</div>

I want to link the other conversation on this to here as well. I’m in support of tweaking how csrf is handled to be more clear on what should be changed.

> [@CSRF invalidation improvements](https://forum.djangoproject.com/t/csrf-invalidation-improvements/25572):
>
> The exception flow for CSRF issues is a bit difficult. I think we can make it easier for developers to determine the root cause of a CSRF invalidation by doing the following: Log a detailed explanation of the error. For example when a CSRF token is missing from the headers, the error message presented to the user is “CSRF token missing.” This doesn’t explain where it’s missing or how it could potentially be added in. For new Django devs this is a very cryptic message. (less sure) Use a unique …

---

_[View the full topic](https://forum.djangoproject.com/t/forwarded-headers-csrf-hints/28616)._
