瀏覽代碼

FB: inserting 'csrf' as a middleware

kaori 4 年之前
父節點
當前提交
160efc3b9b
共有 1 個文件被更改,包括 1 次插入1 次删除
  1. 1 1
      src/server/routes/apiv3/forgot-password.js

+ 1 - 1
src/server/routes/apiv3/forgot-password.js

@@ -60,7 +60,7 @@ module.exports = (crowi) => {
     }
   });
 
-  router.put('/', validator.password, apiV3FormValidator, async(req, res) => {
+  router.put('/', csrf, validator.password, apiV3FormValidator, async(req, res) => {
     const { token, newPassword } = req.body;
 
     const passwordResetOrder = await PasswordResetOrder.findOne({ token });