Description
Creating a token from the Tokens page fails with the error “CSRF validation failed.”
Steps to reproduce:
- Sign in.
- Open the Tokens page.
- Submit the create-token form.
- Observe “CSRF validation failed.”
Expected behavior:
- Valid same-origin token creation succeeds.
- CSRF protection remains enforced for missing or invalid tokens.
- Token value is shown only through the intended one-time success flow.
- Add regression coverage for normal, HTMX, expired-session, and invalid-CSRF submissions.
Sub-issues
0Linked issues
0GitHub
0No branches or pull requests linked.
Comments
0No comments.