Fix CSRF: use getCSRFToken() in getAuthHeaders() to read from cookie
This commit is contained in:
@@ -27,8 +27,9 @@ export function getCSRFToken() {
|
|||||||
export function getAuthHeaders(includeContentType = true) {
|
export function getAuthHeaders(includeContentType = true) {
|
||||||
const headers = {};
|
const headers = {};
|
||||||
if (includeContentType) headers['Content-Type'] = 'application/json';
|
if (includeContentType) headers['Content-Type'] = 'application/json';
|
||||||
// P4: Attach CSRF token for state-changing requests
|
// P4: Attach CSRF token for state-changing requests (read from cookie if memory is empty)
|
||||||
if (csrfToken) headers['x-csrf-token'] = csrfToken;
|
const token = getCSRFToken();
|
||||||
|
if (token) headers['x-csrf-token'] = token;
|
||||||
return headers;
|
return headers;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user