The most scalable and customizable identity server on the market. Replace your Homegrown, Auth0, Okta, Firebase with better UX and DX. Has all the tablestakes: Passkeys, Social Sign In, Multi-Factor Auth, SMS, SAML, TOTP, and more. Written in Go, cloud native, headless, API-first. Available as a service on Ory Network and for self-hosters.
"error": {
"id": "security_csrf_violation",
"code": 403,
"status": "Forbidden",
"reason": "Please retry the flow and optionally clear your cookies. The request was
rejected to protect you from Cross-Site-Request-Forgery (CSRF) which could cause account
takeover, leaking personal information, and other serious security issues.",
"details": {
"docs": "https://www.ory.sh/kratos/docs/debug/csrf",
"hint": "The anti-CSRF cookie was found but the CSRF token was not included in the HTTP request body (csrf_token) nor in the HTTP Header (X-CSRF-Token).",
"reject_reason": "The HTTP Cookie Header was set and a CSRF token was sent but they do not match. We recommend deleting all cookies for this domain and retrying the flow."
},
"message": "the request was rejected to protect you from Cross-Site-Request-Forgery"
}
Preflight checklist
Describe the bug
I use the method that "PATCH https://{your-project-slug-here}.projects.oryapis.com/admin/sessions/{id}/refresh Authorization: Bearer {your-personal-access-token}" according to the https://www.ory.sh/docs/guides/session-management/refresh-extend-sessions. And i'd set the Authorization but it shows that 403 security_csrf_violation
Reproducing the bug
here are my codes
Relevant log output
Relevant configuration
Version
v0.9.0-alpha.2
On which operating system are you observing this issue?
No response
In which environment are you deploying?
No response
Additional Context
NoResponse