We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent 94673ec commit 9c816caCopy full SHA for 9c816ca
templates/app/server/config/express.js
@@ -68,9 +68,11 @@ export default function(app) {
68
* Lusca - express server security
69
* https://github.com/krakenjs/lusca
70
*/
71
- if(env !== 'test' && env !== 'development' && !process.env.SAUCE_USERNAME) { // eslint-disable-line no-process-env
+ if(env !== 'test' && env !== 'development') {
72
app.use(lusca({
73
- csrf: true,
+ csrf: {
74
+ header: 'x-xsrf-token',
75
+ },
76
xframe: 'SAMEORIGIN',
77
hsts: {
78
maxAge: 31536000, //1 year, in seconds
0 commit comments