# How to use Cross Site Request Forgery protection correctly?

**URL:** <https://forum.djangoproject.com/t/how-to-use-cross-site-request-forgery-protection-correctly/6611>\
**Category:** Using Django\
**Created:** [February 16, 2021, 11:23am UTC](https://forum.djangoproject.com/t/how-to-use-cross-site-request-forgery-protection-correctly/6611 "2021-02-16T11:23:03Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![TQuy](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/tquy/32/3033_2.png) [@TQuy](https://forum.djangoproject.com/u/TQuy)\
**Post date:** [February 16, 2021, 11:23am UTC](https://forum.djangoproject.com/t/how-to-use-cross-site-request-forgery-protection-correctly/6611/1 "2021-02-16T11:23:03Z")

</div>

I’ve only started getting into web programming with Django recently. In order to make my website more secure, I used csrf\_token when sending POST request, followed what I saw in  
[https://docs.djangoproject.com/en/3.1/ref/csrf/](https://docs.djangoproject.com/en/3.1/ref/csrf/).  
However, as I included  
`<script src="https://cdn.jsdelivr.net/npm/js-cookie@rc/dist/js.cookie.min.js"></script>`  
in my HTTP file from [Javascrip Cookie Library](https://github.com/js-cookie/js-cookie/), I can get the csrf\_token directly from my browser in Inpsect\>console. I am not sure if doing like that is secure, please give me some pointers.

---

<div class="post-metadata">

**Author:** ![KenWhitesell](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/kenwhitesell/32/280_2.png) [@KenWhitesell](https://forum.djangoproject.com/u/KenWhitesell)\
**Post date:** [February 16, 2021, 12:35pm UTC](https://forum.djangoproject.com/t/how-to-use-cross-site-request-forgery-protection-correctly/6611/2 "2021-02-16T12:35:33Z")

</div>

I’m not sure I understand what you’re asking here, or how the second part relates to the first.  
But in general, the csrf\_token is _not_ a “secret” - it’s just a token that is intended to prevent JavaScript code running from site “A” from submitting forms to site “B”.  
If your question is about retrieving the token from a cookie rather than from the DOM, the CSRF docs page you reference above covers all of that in detail.

---

<div class="post-metadata">

**Author:** ![TQuy](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/tquy/32/3033_2.png) [@TQuy](https://forum.djangoproject.com/u/TQuy)\
**Post date:** [February 16, 2021, 6:07pm UTC](https://forum.djangoproject.com/t/how-to-use-cross-site-request-forgery-protection-correctly/6611/3 "2021-02-16T18:07:00Z")

</div>

I just wonder if the token has to be secret or not, thanks for your answer
