Просмотр исходного кода

do not ignore POST method for csrf

Yohei-Shiina 3 лет назад
Родитель
Сommit
3f0c00b0bd
1 измененных файлов с 1 добавлено и 1 удалено
  1. 1 1
      packages/app/src/server/routes/index.js

+ 1 - 1
packages/app/src/server/routes/index.js

@@ -20,7 +20,7 @@ import * as userActivation from './user-activation';
 const multer = require('multer');
 const multer = require('multer');
 const autoReap = require('multer-autoreap');
 const autoReap = require('multer-autoreap');
 
 
-const csrfProtection = csrf({ ignoreMethods: ['GET', 'HEAD', 'OPTIONS', 'POST'], cookie: false });
+const csrfProtection = csrf({ cookie: false });
 
 
 autoReap.options.reapOnError = true; // continue reaping the file even if an error occurs
 autoReap.options.reapOnError = true; // continue reaping the file even if an error occurs