trackslash
TRACK-39 P2

Fix CSRF validation when creating tokens from the Tokens page

0
All issues

Description

Creating a token from the Tokens page fails with the error “CSRF validation failed.”

Steps to reproduce:

  1. Sign in.
  2. Open the Tokens page.
  3. Submit the create-token form.
  4. Observe “CSRF validation failed.”

Expected behavior:

  • Valid same-origin token creation succeeds.
  • CSRF protection remains enforced for missing or invalid tokens.
  • Token value is shown only through the intended one-time success flow.
  • Add regression coverage for normal, HTMX, expired-session, and invalid-CSRF submissions.

Sub-issues

0

Linked issues

0

GitHub

0

No branches or pull requests linked.

Comments

0
No comments.