Skip to main content

Module csrf

Module csrf 

Source
Expand description

CSRF protection via double-submit cookie.

Verifies state-changing POSTs with a double-submit __Host- cookie compared in constant time.

Constants§

COOKIE_NAME
Names the __Host--prefixed CSRF cookie.
FIELD_NAME

Functions§

current_token
Reads the current token without setting one, safe inside streamed children.
ensure_token
Ensures a request token before headers send, returning "" without a cookie layer.
field
Renders the hidden field embedding the given token.
verify
Verifies the submitted token matches the cookie with a constant-time compare, failing closed with 403.