Skip to content

Commit 2818923

Browse files
committed
Revert "check csrf_protect cookie, not header, in _decode_jwt_from_cookies"
This reverts commit 0be1f35.
1 parent 97e2b2f commit 2818923

File tree

1 file changed

+2
-1
lines changed

1 file changed

+2
-1
lines changed

flask_jwt_extended/utils.py

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -199,7 +199,8 @@ def _decode_jwt_from_cookies(type):
199199
token = _decode_jwt(token, secret, algorithm)
200200

201201
if get_cookie_csrf_protect():
202-
csrf = request.cookies.get(get_access_csrf_cookie_name(), None)
202+
csrf_header_key = get_csrf_header_name()
203+
csrf = request.headers.get(csrf_header_key, None)
203204
if not csrf or not safe_str_cmp(csrf, token['csrf']):
204205
raise NoAuthorizationError("Missing or invalid csrf double submit header")
205206

0 commit comments

Comments
 (0)