我假设没有发送CSRF令牌,这就是验证失败的原因。
以下示例添加了一个带有标记的隐藏字段。此外,在验证过程中还会显示错误,这简化了用户的调试和处理。
from flask import (
Flask,
flash,
redirect,
render_template,
request,
url_for
)
from flask_sqlalchemy import SQLAlchemy
from flask_wtf import FlaskForm
from wtforms import StringField
from wtforms.validators import Email
from wtforms.widgets import TextArea
app = Flask(__name__)
app.config.from_mapping(
SECRET_KEY='Your secret here!',
SQLALCHEMY_DATABASE_URI='sqlite:///demo.db'
)
db = SQLAlchemy(app)
class ContactInfo(db.Model):
id = db.Column(db.Integer, primary_key=True)
name = db.Column(db.String, nullable=False)
email = db.Column(db.String, nullable=True)
phone_number = db.Column(db.String, nullable=True)
message = db.Column(db.String, nullable=True)
contact_date = db.Column(db.DateTime, nullable=False, server_default=db.func.now())
class ContactInfoForm(FlaskForm):
name = StringField(
'Nombre',
render_kw={ 'placeholder': 'Nombre', }
)
email = StringField(
'Correo electrónico',
validators=[Email()],
render_kw={ 'placeholder': 'Email', }
)
phone_number = StringField(
'Número de teléfono',
render_kw={ 'placeholder': 'Teléfono', }
)
message = StringField(
'Mensaje',
widget=TextArea(),
render_kw={ 'placeholder': 'Mensaje', }
)
with app.app_context():
db.drop_all()
db.create_all()
@app.route('/contacto', methods=['GET', 'POST'])
def contact():
form = ContactInfoForm(request.form)
if form.validate_on_submit():
contact_info = ContactInfo()
form.populate_obj(contact_info)
db.session.add(contact_info)
db.session.commit()
# ...
flash(
'Muchas gracias por la información, en la brevedad '\
'nos pondremos en contacto con usted.','success'
)
return redirect(url_for('.contact', _anchor='form'))
return render_template('contact.html', **locals())
<form method="POST">
{{ form.csrf_token }}
<div>
{{ form.name.label() }}
{{ form.name(class_='feedback-input') }}
{% if form.name.errors -%}
<ul>
{% for error in form.name.errors -%}
<li>{{ error }}</li>
{% endfor -%}
</ul>
{% endif -%}
</div>
<div>
{{ form.email.label() }}
{{ form.email(class_='feedback-input') }}
{% if form.email.errors -%}
<ul>
{% for error in form.email.errors -%}
<li>{{ error }}</li>
{% endfor -%}
</ul>
{% endif -%}
</div>
<div>
{{ form.phone_number.label() }}
{{ form.phone_number(class_='feedback-input') }}
{% if form.phone_number.errors -%}
<ul>
{% for error in form.phone_number.errors -%}
<li>{{ error }}</li>
{% endfor -%}
</ul>
{% endif -%}
</div>
<div>
{{ form.message.label() }}
{{ form.message(class_='feedback-input') }}
{% if form.message.errors -%}
<ul>
{% for error in form.message.errors -%}
<li>{{ error }}</li>
{% endfor -%}
</ul>
{% endif -%}
</div>
<button type="submit">Enviar</button>
</form>