Hi so here's the problem: I'm doing a login through ajax without page reloading - just click Login button giving your username and password and a request with two cookies, sessionid and csrftoken, is coming. Note that page has NOT been reloaded. Right after I am triggering another ajax (POST) request which requires logged in user:
@login_required
@ajax
def member_index(request):
....
I get a 403 Forbidden error which comes from CsrfMiddleware (because if I turn it off in settings, everything works). The question is what I am doing wrong? If I reload the page, the ajax request works. I have sniffed the cookies in the browser (sessionid and csrftoken) and it looks everything is set good. ]