-
-
Notifications
You must be signed in to change notification settings - Fork 2.2k
fix: disable CSRF checks in dev #14335
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
🦋 Changeset detectedLatest commit: bca2764 The changes in this PR will be included in the next version bump. This PR includes changesets to release 1 package
Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
dummdidumm
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
worth a callout in the docs somewhere? not sure where, and not in any way blocking
|
good point — added to the |
|
@Rich-Harris I've talked to people on Discord that seemed to be running "npm run dev" in production. It's not a valid use case but I wonder if we won't accidentally enable a sudden security hole for these people, which can come back in form of badwill? This change sounds like something for Kit 3.x imho. Wouldn't it be possible to have remote functions respect |
|
I... what? How? How does someone end up in that situation? It's literally called
That's a separate conversation to 'should the origin be checked?' and the answer is no — if something other than your own origin is calling remote functions, it's a bad request, period |
#14309 (comment)
closes #14309
Please don't delete this checklist! Before submitting the PR, please make sure you do the following:
Tests
pnpm testand lint the project withpnpm lintandpnpm checkChangesets
pnpm changesetand following the prompts. Changesets that add features should beminorand those that fix bugs should bepatch. Please prefix changeset messages withfeat:,fix:, orchore:.Edits