Update csrf-sync to fallback to _csrf query param

This commit is contained in:
psibean
2023-02-01 23:13:18 +10:30
committed by Julian Lam
parent bb0397cbc8
commit f553da48e1

View File

@@ -6,6 +6,13 @@ const {
generateToken,
csrfSynchronisedProtection,
} = csrfSync({
getTokenFromRequest: (req) => {
if (req.headers['x-csrf-token']) {
return req.headers['x-csrf-token'];
} else if (req.query) {
return req.query._csrf;
}
},
size: 64,
});