to enter (POST) with the token, of course, you must first get the CSRF token, as you said. if you first call GET on the login page (before you follow the POST), the result of the login page will be returned csrf_token, which you can see if you use a browser (with the developer toolbar open) and look at the network panel according to response content to view the csrftoken cookie set by the server. in my case:
Set-Cookie:csrftoken=PgQEgY3LAynbVeWRIzXoo2VFRLfd8Uqt; expires=Fri, 10-Nov-2017 18:59:54 GMT; Max-Age=31449600; Path=/; secure
after parsing this answer, set the header, for example:
X-CSRFToken: "PgQEgY3LAynbVeWRIzXoo2VFRLfd8Uqt"
in your POST with login / password information. Hth
matias elgart
source share