Skip to content

Skip CSRF for embeds#402

Merged
thomiceli merged 2 commits into
thomiceli:masterfrom
x-way:no-csrf-for-embeds
Jan 20, 2025
Merged

Skip CSRF for embeds#402
thomiceli merged 2 commits into
thomiceli:masterfrom
x-way:no-csrf-for-embeds

Conversation

@x-way

@x-way x-way commented Dec 17, 2024

Copy link
Copy Markdown
Contributor

The CSRF middleware sets a _csrf cookie also for loading the embed javascript on third-party sites. With this change no _csrf cookie is set when loading the embed javascript (regardless if third-party site or first-party).

@x-way x-way force-pushed the no-csrf-for-embeds branch from be6715c to 9d59a92 Compare December 17, 2024 20:05
The CSRF middleware sets a _csrf cookie also for loading the embed
javascript on third-party sites. With this change no _csrf cookie is set
when loading the embed javascript (regardless if third-party site or
first-party).

# Conflicts:
#	internal/web/server.go
@thomiceli thomiceli merged commit a752e05 into thomiceli:master Jan 20, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants