diff options
| author | Peter Stone <thepeterstone@gmail.com> | 2026-01-20 17:02:16 -1000 |
|---|---|---|
| committer | Peter Stone <thepeterstone@gmail.com> | 2026-01-20 17:02:16 -1000 |
| commit | 6cdfc55e5712075fef24a559138c054ef58e1ac1 (patch) | |
| tree | ba2a78bb10c4664c4b370107116f19c0250a7f2c /instructions.md | |
| parent | 5b6defbc8c3082013a86b727b4c75370ba3385c7 (diff) | |
Fix CSRF token missing from refresh fetch requests
Manual JavaScript fetch() calls weren't including the CSRF token,
causing 403 Forbidden on /api/refresh. Extract token from
hx-headers body attribute and include in all POST requests.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
Diffstat (limited to 'instructions.md')
0 files changed, 0 insertions, 0 deletions
