Skip to content

csrf-middleware v0.2.0

Choose a tag to compare

@github-actions github-actions released this 28 Sep 21:45
c9c8939

Minor Changes

  • BREAKING CHANGE: csrf() now reads submitted tokens from headers and parsed form fields only by default. Requests that supply a token only in the query string are rejected. Applications that need query parameter tokens can retain that behavior with an explicit value resolver, which replaces the default lookup:

    -csrf()
    +csrf({
    +  value(context) {
    +    return context.url.searchParams.get('_csrf')
    +  },
    +})

Patch Changes