Closed lnielsen closed 1 year ago
CSRF_HEADER_NAME should not be HTTP_X_CSRFTOKEN but instead X-CSRFToken
CSRF_HEADER_NAME
HTTP_X_CSRFTOKEN
X-CSRFToken
closing, this was fixed by @lnielsen here https://github.com/inveniosoftware/invenio-rest/commit/3e2a4d03270f19e494457f14d8a7626210115708
CSRF_HEADER_NAME
should not beHTTP_X_CSRFTOKEN
but insteadX-CSRFToken