| 1 |   | This is a ticket to keep track of general CSRF improvements we want to add to Django. | 
          
          
            | 2 |   |  | 
          
          
            | 3 |   | This includes: | 
          
          
            | 4 |   |  | 
          
          
            | 5 |   |  * #16010 - add Origin checking | 
          
          
            | 6 |   |  * Optionally tie CSRF to sessions | 
          
          
            | 7 |   |  * Use signing to improve CSRF (maybe with sessions) | 
          
          
            | 8 |   |  * Improve domain/host checking - deal with the subdomain to subdomain problem | 
          
          
            |   | 1 | Storing the CSRF token in a cookie (Django's default) is safe, but storing it in the session is common practice in other web frameworks and therefore sometimes demanded by security auditors. |