This repository was archived by the owner on May 1, 2021. It is now read-only.
-
Notifications
You must be signed in to change notification settings - Fork 0
feat: CSRF protection #48
Copy link
Copy link
Open
Labels
enhancementNew feature or requestNew feature or requesthelp wantedExtra attention is neededExtra attention is neededpriority:mediumA task that should be finished or fixed as soon as there is nothing more importantA task that should be finished or fixed as soon as there is nothing more important
Milestone
Description
Is your feature request related to a problem? Please describe.
Atm no CSRF protection is in place, giving warnings from both Github and LGTM.
Describe the solution you'd like
Implement CSRF protection middleware for all API routes.
Describe alternatives you've considered
N/A
Additional context
- https://github.com/expressjs/csurf - Possible solution?
- https://owasp.org/www-community/attacks/csrf - What is CSRF? (OWASP page)
Metadata
Metadata
Assignees
Labels
enhancementNew feature or requestNew feature or requesthelp wantedExtra attention is neededExtra attention is neededpriority:mediumA task that should be finished or fixed as soon as there is nothing more importantA task that should be finished or fixed as soon as there is nothing more important