aboutsummaryrefslogtreecommitdiffstats
path: root/docs/topics/ajax-csrf-cors.md
diff options
context:
space:
mode:
authorTom Christie2013-10-03 15:18:47 +0100
committerTom Christie2013-10-03 15:18:47 +0100
commitafc9e9e03868634c548178e6730a0f9964f398c0 (patch)
treeac12804aa0ef0cb73a4506177500d0596b2c883a /docs/topics/ajax-csrf-cors.md
parentf6301636fb52dc6e02fd55e1c07c0be0a3b4ebfd (diff)
parent38049d11b63cdcc7f2a71ac51600182545912350 (diff)
downloaddjango-rest-framework-afc9e9e03868634c548178e6730a0f9964f398c0.tar.bz2
Merge branch 'master' of https://github.com/tomchristie/django-rest-framework
Diffstat (limited to 'docs/topics/ajax-csrf-cors.md')
-rw-r--r--docs/topics/ajax-csrf-cors.md2
1 files changed, 1 insertions, 1 deletions
diff --git a/docs/topics/ajax-csrf-cors.md b/docs/topics/ajax-csrf-cors.md
index 0555b84d..97dd4710 100644
--- a/docs/topics/ajax-csrf-cors.md
+++ b/docs/topics/ajax-csrf-cors.md
@@ -6,7 +6,7 @@
## Javascript clients
-If your building a javascript client to interface with your Web API, you'll need to consider if the client can use the same authentication policy that is used by the rest of the website, and also determine if you need to use CSRF tokens or CORS headers.
+If you’re building a JavaScript client to interface with your Web API, you'll need to consider if the client can use the same authentication policy that is used by the rest of the website, and also determine if you need to use CSRF tokens or CORS headers.
AJAX requests that are made within the same context as the API they are interacting with will typically use `SessionAuthentication`. This ensures that once a user has logged in, any AJAX requests made can be authenticated using the same session-based authentication that is used for the rest of the website.