Fix CSRF: use getCSRFToken() in getAuthHeaders() to read from cookie
This commit is contained in:
@@ -27,8 +27,9 @@ export function getCSRFToken() {
|
||||
export function getAuthHeaders(includeContentType = true) {
|
||||
const headers = {};
|
||||
if (includeContentType) headers['Content-Type'] = 'application/json';
|
||||
// P4: Attach CSRF token for state-changing requests
|
||||
if (csrfToken) headers['x-csrf-token'] = csrfToken;
|
||||
// P4: Attach CSRF token for state-changing requests (read from cookie if memory is empty)
|
||||
const token = getCSRFToken();
|
||||
if (token) headers['x-csrf-token'] = token;
|
||||
return headers;
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user