RVRNEXT-2 disable anti csrf check in case of oauth token
rvr-nextgen/pipeline/pr-master This commit looks good

This commit is contained in:
bence committed 2023-04-08 20:02:02 +02:00
1 parent 84df948012
commit bc9f1a1d1f
2 files changed
+4 -1

No files matched your search

+3
View File
@@ -78,3 +78,6 @@ Container::$request = new SokoWeb\Request\Request(
if (!Container::$request->session()->has('anti_csrf_token')) {
Container::$request->session()->set('anti_csrf_token', bin2hex(random_bytes(16)));
}
//TODO: make a nicer logic
$antiCsrfTokenExceptions = ['oauth/token'];