Skip to content

CSRF Protection - also check the header #61

@adamsch1

Description

@adamsch1

Hi -

I was reading the CSRF guard code. Would the authors be opposed to also checking for the csrf key/value set in a X header like X-CSRF-Token ?? It's easier in come scenarios [AngularJS] to use the header.

if there is interest I will submit a patch

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions