Skip to content

XSRF-TOKEN httpOnly cookie #644

@thiagomdiniz

Description

@thiagomdiniz

Hi,
It seems that a security feature added in version 4.1.0 is preventing us from updating Agate, because our corporate firewall forces all cookies to be httpOnly, and from what I've checked, the added feature requires JavaScript to access the XSRF-TOKEN cookie in order to send the x-xsrf-token header in requests.

Would it be possible to validate the xsrf only through the httpOnly cookie?

References:

Thank you!

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions