CSRF checks fail with a standard EZproxy instance

A woman looking perplexed as her CSRF headers disappear in to the void
What’s going on

So what can you do

  1. reach out to all your customers who use a proxy and ask them nicely to update their proxy configurations
  2. implement a workaround where you pass the CSRF token to the server a different way and rewrite or extend your framework’s CSRF validation middleware to handle it
  3. turn off CSRF validation




Tim Barclay

