Issues
- 1
CSRF token is mismatch even in correct things.
#154 opened by Fyphen1223 - 1
Rename csrf blacklist/whitelist configs
#143 opened by JevinAnderson - 0
CSRF token missing at app.use(lusca.csrf())
#135 opened by darklight147 - 0
Setting CSRF token on the blacklisted routes.
#142 opened by ohpyupi - 2
Nonce is not being generated
#136 opened by danielcl - 0
- 1
Cookie “XSRF-TOKEN” will be soon rejected
#139 opened by miclill - 0
Change CSRF-Token name
#138 opened by molerat619 - 0
- 0
How skip api css js avoid redundant?
#134 opened by lichspace - 0
lusca requires req.session
#133 opened by matharuajay - 12
- 0
DNS Rebinding protection
#131 opened by brannondorsey - 2
Is helmet needed with lusca?
#127 opened by khaledosman - 0
update tests and dependencies
#107 opened by gabrielcsapo - 2
How to send post with CSRF token without manually adding a form or whitelisting/blacklisting
#126 opened by djaffer - 2
Support CSRF black/white listing on URL params
#123 opened by mjy78 - 1
X-XSS-Protection report uri
#124 opened by theel0ja - 1
CSRF blacklist and whitelist not working as expected for multiple endpoints.
#128 opened by gladchinda - 2
Exempting XSRF-TOKEN for some requests
#119 opened by beshad - 2
- 3
CSRF error status code
#116 opened by zisiszikos - 1
CSRF: Disable error log?
#62 opened by uptownhr - 3
Error: CSRF token mismatch
#97 opened by erbridge - 2
- 0
CSRF: Move from 10 Bytes to 9 or 12.
#109 opened by jagracey - 5
- 0
- 1
- 6
Secure csrf
#78 opened by mrazvan21 - 0
- 11
Error: CSRF token missing
#58 opened by makromat - 0
|
#98 opened by SensationSama - 1
- 3
Lusca + Angular2 Problems
#93 opened by vgogov - 3
socket.io Content-Security-Policy Host
#90 opened by theage - 3
Lusca and nginx best practices
#89 opened by titoesteves - 2
how to allow bypass security from one route
#92 opened by luisfusim - 1
support for CSP's block-all-mixed-content
#69 opened by turboMaCk - 9
Error: CSRF token missing
#54 opened by anjali-chadha - 18
CSRF Query
#61 opened by gabeio - 0
- 4
- 7
Invalidate CSRF token
#68 opened by kumarmugu - 2
REST API sessionless
#64 opened by fondberg - 3
lusca with client-sesson fails
#65 opened by muthu-cs - 1
CSRF Hooks
#63 opened by uptownhr - 2
IE and Safari block third-party cookies, by default causing csrf issues in iframe
#53 opened by shaunwarman - 0
Test issue
#52 opened by jeffharrell - 3
A way to defer the header setup
#48 opened by facundocabrera