RVRNEXT-2 disable anti csrf check in case of oauth token
rvr-nextgen/pipeline/pr-master This commit looks good
rvr-nextgen/pipeline/pr-master This commit looks good
This commit is contained in:
2 files changed
+4
-1
No files matched your search
@@ -78,3 +78,6 @@ Container::$request = new SokoWeb\Request\Request(
|
||||
if (!Container::$request->session()->has('anti_csrf_token')) {
|
||||
Container::$request->session()->set('anti_csrf_token', bin2hex(random_bytes(16)));
|
||||
}
|
||||
|
||||
//TODO: make a nicer logic
|
||||
$antiCsrfTokenExceptions = ['oauth/token'];
|
||||
Reference in new issue
Block a user