Skip to content

Commit 0be1f35

Browse files
committed
check csrf_protect cookie, not header, in _decode_jwt_from_cookies
1 parent cea3c4b commit 0be1f35

File tree

1 file changed

+1
-2
lines changed

1 file changed

+1
-2
lines changed

flask_jwt_extended/utils.py

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -199,8 +199,7 @@ def _decode_jwt_from_cookies(type):
199199
token = _decode_jwt(token, secret, algorithm)
200200

201201
if get_cookie_csrf_protect():
202-
csrf_header_key = get_csrf_header_name()
203-
csrf = request.headers.get(csrf_header_key, None)
202+
csrf = request.cookies.get(get_access_csrf_cookie_name(), None)
204203
if not csrf or not safe_str_cmp(csrf, token['csrf']):
205204
raise NoAuthorizationError("Missing or invalid csrf double submit header")
206205

0 commit comments

Comments
 (0)