mirror of
https://github.com/freeCodeCamp/freeCodeCamp.git
synced 2026-09-24 23:01:18 +08:00
fix: allow csrf_token to expire with session (#51893)
This commit is contained in:
@@ -33,6 +33,8 @@ export const wrapPageElement = layoutSelector;
|
||||
export const disableCorePrefetching = () => true;
|
||||
|
||||
export const onClientEntry = () => {
|
||||
// the token must be erased since it is only valid for the old _csrf secret
|
||||
// Letting the users' browsers expire the cookie seems to have caused issues
|
||||
// for some users. Until we have time to investigate further, we should remove
|
||||
// the cookie on every page load.
|
||||
cookies.erase('csrf_token');
|
||||
};
|
||||
|
||||
Reference in New Issue
Block a user