我试图复制Alex Kuhl在他的优秀帖子中给出的例子:http://kuhlit.blogspot.com/2011/04/ajax-file-uploads-and-csrf-in-django-13.html
####### upload_page.html
{% extends "base.html" %}
{% load i18n %}
{% block title %}Blog Post: Upload Files.{% endblock %}
{% block content %}
<div id="maintext">
<p>To upload a file, click on the button below.</p>
<div id="file-uploader">
<p>Please enable JavaScript to use file uploader.</p>
<!-- or put a simple form for upload here -->
function createUploader(){
var uploader = new qq.FileUploader( {
action: "{% url ajax_upload %}",
element: $('#file-uploader')[0],
multiple: false,
onComplete: function( id, fileName, responseJSON ) {
if( responseJSON.success )
alert( "success!" ) ;
alert( "Sorry, your upload has failed! Please contact us by telephone or email." ) ;
onAllComplete: function( uploads ) {
// uploads is an array of maps
// the maps look like this: { file: FileObject, response: JSONServerResponse }
alert( "All complete!" ) ;
params: {
'csrf_token': '{{ csrf_token }}',
'csrf_name': 'csrfmiddlewaretoken',
'csrf_xname': 'X-CSRFToken',
} ) ;
// in your app create uploader as soon as the DOM is ready
// don't wait for the window to load
window.onload = createUploader;
{% endblock %}
############### views.py
def upload_page( request ):
ctx = RequestContext( request, {
'csrf_token': get_token( request ),
return render_to_response( 'success/upload_page.html', ctx )
def save_upload( uploaded, filename, raw_data ):
filename = settings.UPLOAD_STORAGE_DIR
raw_data: if True, uploaded is an HttpRequest object with the file being
the raw post data
if False, uploaded has been submitted via the basic form
submission and is a regular Django UploadedFile in request.FILES
from io import FileIO, BufferedWriter
with BufferedWriter( FileIO( filename, "wb" ) ) as dest:
# if the "advanced" upload, read directly from the HTTP request
# with the Django 1.3 functionality
if raw_data:
foo = uploaded.read( 1024 )
while foo:
dest.write( foo )
foo = uploaded.read( 1024 )
# if not raw, it was a form upload so read in the normal Django chunks fashion
for c in uploaded.chunks( ):
dest.write( c )
# got through saving the upload, report success
return True
except IOError:
# could not open the file most likely
return False
def ajax_upload( request ):
if request.method == "POST":
if request.is_ajax( ):
# the file is stored raw in the request
upload = request
is_raw = True
# AJAX Upload will pass the filename in the querystring if it is the "advanced" ajax upload
filename = request.GET[ 'qqfile' ]
except KeyError:
return HttpResponseBadRequest( "AJAX request not valid" )
# not an ajax upload, so it was the "basic" iframe version with submission via form
is_raw = False
if len( request.FILES ) == 1:
upload = request.FILES.values( )[ 0 ]
raise Http404( "Bad Upload" )
filename = upload.name
# save the file
success = save_upload( upload, filename, is_raw )
# let Ajax Upload know whether we saved it or not
import json
ret_json = { 'success': success, }
return HttpResponse( json.dumps( ret_json ) )
####### urls.pyurlpatterns = patterns('',
(r'media/(?P<path>.*)$', 'django.views.static.serve', {'document_root': settings.MEDIA_ROOT}),
(r'^media/(?P<path>.*)$', 'django.views.static.serve', {'document_root': settings.MEDIA_ROOT}),
url(r'^$', index,name='home'),
url( r'^ajax_upload$', ajax_upload, name="ajax_upload" ),
url( r'^upload/$', upload_page, name="upload_page" ),
(r'^admin/', include(admin.site.urls)),
(r'^accounts/', include('regfields.urls')),
# Examples:
# url(r'^$', 'mysite.views.home', name='home'),
# url(r'^mysite/', include('mysite.foo.urls')),
# Uncomment the admin/doc line below to enable admin documentation:
# url(r'^admin/doc/', include('django.contrib.admindocs.urls')),
# Uncomment the next line to enable the admin:
# url(r'^admin/', include(admin.site.urls)),
我使用:filename = settings.UPLOAD_STORAGE_DIR,其中,UPLOAD_STORAGE_DIR在settings.py中被定义为'/ media /'
答案 0 :(得分:4)
您的Javascript中存在拼写错误。它应该是{% csrf_token %}
而不是{{ csrf_token }}
修改强> 在您发表评论之后,我仔细查看了您链接的文章。
答案 1 :(得分:1)
您需要将return True
if raw_data:
foo = uploaded.read(1024)
while foo:
foo = uploaded.read(1024)
return True