lusca icon indicating copy to clipboard operation
lusca copied to clipboard

Setting CSRF token on the blacklisted routes.

Open ohpyupi opened this issue 4 years ago • 0 comments

Hi. It seems like for end points that are blacklisted by Lusca, it does not set CSRF tokens for the requests at all.

So what can happen is for the POST endpoint where a page is being rendered, because Lusca does not set CSRF token, it cannot make subsequent POST calls after the page is rendered.

Is it a part of design or a missing feature?

ohpyupi avatar Oct 02 '20 22:10 ohpyupi