We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
1 parent cea3c4b commit 0be1f35Copy full SHA for 0be1f35
flask_jwt_extended/utils.py
@@ -199,8 +199,7 @@ def _decode_jwt_from_cookies(type):
199
token = _decode_jwt(token, secret, algorithm)
200
201
if get_cookie_csrf_protect():
202
- csrf_header_key = get_csrf_header_name()
203
- csrf = request.headers.get(csrf_header_key, None)
+ csrf = request.cookies.get(get_access_csrf_cookie_name(), None)
204
if not csrf or not safe_str_cmp(csrf, token['csrf']):
205
raise NoAuthorizationError("Missing or invalid csrf double submit header")
206
0 commit comments