koajs / csrf

CSRF tokens for koa
MIT License
264 stars 32 forks source link

koa-csrf

build status build status code style styled with prettier made with lass license

CSRF tokens for Koa

NOTE: As of v5.0.0+ ctx.csrf, ctx_csrf, and ctx.response.csrf are removed – instead use ctx.state._csrf. Furthermore we have dropped invalidTokenMessage and invalidTokenStatusCode in favor of an errorHandler function option.

Table of Contents

Install

npm:

npm install koa-csrf

Usage

  1. Add middleware in Koa app (see options below):

    const Koa = require('koa');
    const bodyParser = require('koa-bodyparser');
    const session = require('koa-generic-session');
    const convert = require('koa-convert');
    const CSRF = require('koa-csrf');
    
    const app = new Koa();
    
    // set the session keys
    app.keys = [ 'a', 'b' ];
    
    // add session support
    app.use(convert(session()));
    
    // add body parsing
    app.use(bodyParser());
    
    // add the CSRF middleware
    app.use(new CSRF());
    
    // your middleware here (e.g. parse a form submit)
    app.use((ctx, next) => {
     if (![ 'GET', 'POST' ].includes(ctx.method))
       return next();
     if (ctx.method === 'GET') {
       ctx.body = ctx.state._csrf;
       return;
     }
     ctx.body = 'OK';
    });
    
    app.listen();
  2. Add the CSRF token in your template forms:

    Jade Template:

    form(action='/register', method='POST')
     input(type='hidden', name='_csrf', value=_csrf)
     input(type='email', name='email', placeholder='Email')
     input(type='password', name='password', placeholder='Password')
     button(type='submit') Register

    EJS Template:

    <form action="/register" method="POST">
     <input type="hidden" name="_csrf" value="<%= _csrf %>" />
     <input type="email" name="email" placeholder="Email" />
     <input type="password" name="password" placeholder="Password" />
     <button type="submit">Register</button>
    </form>

Options

Contributors

Name Website
Nick Baugh https://github.com/niftylettuce
Imed Jaberi https://www.3imed-jaberi.com/

License

MIT © Jonathan Ong