Skip to content

fix: keep the CSRF token stable per browser and retry once on CSRF_INVALID - #8

Merged
vantanminh merged 1 commit into
mainfrom
fix/csrf-stable-token
Oct 3, 2026
Merged

vantanminh merged 1 commit into
mainfrom
fix/csrf-stable-token

Conversation

@vantanminh

Copy link
Copy Markdown
Owner

Summary

On prod, POST /api/v1/integrations/knotree-registry/authorize (and any mutation) can fail with 403 CSRF_INVALID.

Cause: the CSRF cookie is shared by every tab, but each tab caches its own token in memory. Any later call to /auth/csrf (another tab, a reload, signing in again) overwrites the cookie, so the older tab sends a stale header.

Fix:

  • /auth/csrf reuses the browser's existing, well-formed CSRF cookie instead of minting a new one every time.
  • apiRequest resets its cached token and retries once on CSRF_INVALID / CSRF_REQUIRED.

This commit was pushed to #7 after that PR had already merged, so it was not included in that deploy.

Test plan

  • cargo test for the API against Postgres: 119 passed, including the new csrf_reuses_the_browsers_current_token.
  • New web test src/lib/api.test.ts: a stale token gets refreshed and the request is retried once.
  • tsc --noEmit

🤖 Generated with Claude Code

…VALID

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@vantanminh
vantanminh merged commit b336f14 into main Oct 3, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant