Browse Source

Merge pull request #423 from m0sth8/fix-xcsrf-token

Set headers in js and go files to X-Csrf-Token
无闻 10 years ago
parent
commit
f19fc230d4
1 changed files with 1 additions and 0 deletions
  1. 1 0
      cmd/web.go

+ 1 - 0
cmd/web.go

@@ -95,6 +95,7 @@ func newMacaron() *macaron.Macaron {
 	m.Use(csrf.Generate(csrf.Options{
 		Secret:    setting.SecretKey,
 		SetCookie: true,
+		Header:    "X-Csrf-Token",
 	}))
 	m.Use(toolbox.Toolboxer(m, toolbox.Options{
 		HealthCheckFuncs: []*toolbox.HealthCheckFuncDesc{