Skip to content

fix(security): exempt agent heartbeat from CSRF middleware#3072

Merged
mrveiss merged 1 commit intoDev_new_guifrom
fix/csrf-heartbeat-exempt
Mar 31, 2026
Merged

fix(security): exempt agent heartbeat from CSRF middleware#3072
mrveiss merged 1 commit intoDev_new_guifrom
fix/csrf-heartbeat-exempt

Conversation

@mrveiss
Copy link
Copy Markdown
Owner

@mrveiss mrveiss commented Mar 31, 2026

Agent heartbeats (POST /api/nodes/{id}/heartbeat) were blocked by CSRF middleware requiring Authorization header. Agent uses service-to-service calls without browser auth.

@mrveiss mrveiss merged commit 39136c6 into Dev_new_gui Mar 31, 2026
1 check failed
@mrveiss mrveiss deleted the fix/csrf-heartbeat-exempt branch March 31, 2026 17:49
@github-actions
Copy link
Copy Markdown

✅ SSOT Configuration Compliance: Passing

🎉 No hardcoded values detected that have SSOT config equivalents!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant