We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
I'm not sure how koa-csrf intercepts HTTP requests - does it matter if I set my koa-router middleware before or after setting koa-csrf?
koa-csrf
koa-router
This is what I'm using now:
server.use(new CSRF({ invalidSessionSecretMessage: 'Invalid session secret', invalidSessionSecretStatusCode: 403, invalidTokenMessage: 'Invalid CSRF token', invalidTokenStatusCode: 403, excludedMethods: ['GET', 'HEAD', 'OPTIONS'], disableQuery: false })); server.use(router.routes());
The text was updated successfully, but these errors were encountered:
You should use koa-csrf before you define your routes. Generally speaking, global middleware should always be "first" in your stack.
Sorry, something went wrong.
No branches or pull requests
I'm not sure how
koa-csrf
intercepts HTTP requests - does it matter if I set mykoa-router
middleware before or after settingkoa-csrf
?This is what I'm using now:
The text was updated successfully, but these errors were encountered: