Commit e0699f9
committed
fix: Re-add CSRF exclusions for admin routes
CSRF validation was failing even with correct token being sent.
Re-adding exclusions for:
- /admin/api-keys/ (session-authenticated)
- /admin/sync (HTMX sends token)
- /admin/settings (HTMX sends token)
These routes are still protected by session authentication.
TODO: Investigate why CSRF validation fails with Litestar.1 parent 1a716ad commit e0699f9
3 files changed
+8
-2
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
3 | | - | |
| 3 | + | |
4 | 4 | | |
5 | 5 | | |
6 | 6 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
3 | | - | |
| 3 | + | |
4 | 4 | | |
5 | 5 | | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
127 | 127 | | |
128 | 128 | | |
129 | 129 | | |
| 130 | + | |
| 131 | + | |
| 132 | + | |
| 133 | + | |
| 134 | + | |
| 135 | + | |
130 | 136 | | |
131 | 137 | | |
132 | 138 | | |
| |||
0 commit comments