mirror of
https://github.com/NodeBB/NodeBB.git
synced 2025-11-03 04:25:55 +01:00
fix: update csrf parser to accept csrf_token form value if present
This commit is contained in:
@@ -9,8 +9,8 @@ const {
|
||||
getTokenFromRequest: (req) => {
|
||||
if (req.headers['x-csrf-token']) {
|
||||
return req.headers['x-csrf-token'];
|
||||
} else if (req.query) {
|
||||
return req.query._csrf;
|
||||
} else if (req.body.csrf_token) {
|
||||
return req.body.csrf_token;
|
||||
}
|
||||
},
|
||||
size: 64,
|
||||
|
||||
Reference in New Issue
Block a user