Skip to content

fix: support CSRF flow in auth setup and account prepare#1

Open
yandex-praktikum wants to merge 1 commit intomainfrom
fix/csrf-auth-setup
Open

fix: support CSRF flow in auth setup and account prepare#1
yandex-praktikum wants to merge 1 commit intomainfrom
fix/csrf-auth-setup

Conversation

@yandex-praktikum
Copy link

@yandex-praktikum yandex-praktikum commented Feb 26, 2026

Что сделано

  • добавлен CSRF-handshake в src/utils.js перед POST /auth/register
  • добавлено получение CSRF токена в __tests__/global.setup.ts перед POST /auth/login
  • в auth-запросы добавлен заголовок X-CSRF-Token

Зачем

Canonical backend (commit 50909dc) требует CSRF для login/register, без этого setup и prepare падают с 403.

Проверка

  • node --check src/utils.js
  • npm run test -- --list

@girolle girolle requested a review from rpill February 26, 2026 12:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants