From dd095d9696fd2f76538330c67d303ad3978cbfde Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?K=C3=BChn?= Date: Tue, 25 Aug 2026 12:17:08 +0200 Subject: [PATCH] Fix CSRF: use getCSRFToken() in getAuthHeaders() to read from cookie --- frontend/src/utils/api.js | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/frontend/src/utils/api.js b/frontend/src/utils/api.js index 0f6371e..e369e22 100644 --- a/frontend/src/utils/api.js +++ b/frontend/src/utils/api.js @@ -27,8 +27,9 @@ export function getCSRFToken() { export function getAuthHeaders(includeContentType = true) { const headers = {}; if (includeContentType) headers['Content-Type'] = 'application/json'; - // P4: Attach CSRF token for state-changing requests - if (csrfToken) headers['x-csrf-token'] = csrfToken; + // P4: Attach CSRF token for state-changing requests (read from cookie if memory is empty) + const token = getCSRFToken(); + if (token) headers['x-csrf-token'] = token; return headers; }