Skip to content

Commit 9c816ca

Browse files
committed
fix(server): fix CSRF for Angular
1 parent 94673ec commit 9c816ca

File tree

1 file changed

+4
-2
lines changed

1 file changed

+4
-2
lines changed

Diff for: templates/app/server/config/express.js

+4-2
Original file line numberDiff line numberDiff line change
@@ -68,9 +68,11 @@ export default function(app) {
6868
* Lusca - express server security
6969
* https://github.com/krakenjs/lusca
7070
*/
71-
if(env !== 'test' && env !== 'development' && !process.env.SAUCE_USERNAME) { // eslint-disable-line no-process-env
71+
if(env !== 'test' && env !== 'development') {
7272
app.use(lusca({
73-
csrf: true,
73+
csrf: {
74+
header: 'x-xsrf-token',
75+
},
7476
xframe: 'SAMEORIGIN',
7577
hsts: {
7678
maxAge: 31536000, //1 year, in seconds

0 commit comments

Comments
 (0)