From 225a0fbd059781fa262148e6a21e8f27d6303638 Mon Sep 17 00:00:00 2001 From: Oliver Eyton-Williams Date: Fri, 13 Oct 2023 00:10:37 +0200 Subject: [PATCH] fix: allow csrf_token to expire with session (#51893) --- client/gatsby-browser.js | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/client/gatsby-browser.js b/client/gatsby-browser.js index 96f824f533c..6b6a26033f8 100644 --- a/client/gatsby-browser.js +++ b/client/gatsby-browser.js @@ -33,6 +33,8 @@ export const wrapPageElement = layoutSelector; export const disableCorePrefetching = () => true; export const onClientEntry = () => { - // the token must be erased since it is only valid for the old _csrf secret + // Letting the users' browsers expire the cookie seems to have caused issues + // for some users. Until we have time to investigate further, we should remove + // the cookie on every page load. cookies.erase('csrf_token'); };