Exception CSRF check for routers node js

Viewed 59

I am using webook to call one of my routers in my node js application. I want to not use 'csurf' which is a library for CSRF token when that specific router is called. The router is called ch and it is not the index router

My code for the CSRF expection is like this

var csrf = require('csurf');
var csrfProtection = csrf();


var csrfExclusion = ['/check-ch'];
var conditionalCSRF = function (req, res, next) {
    if(csrfExclusion.indexOf(req.path) !== -1){
        next();
    } else {
        csrf(req, res, next);
        next();
    }
}
router.use(conditionalCSRF);

router.post('/check-ch',(req, res, next) => {
    console.log(req.body);
    console.log('i am here');
});

Normally I searched stackoverflow but all answer shows that the method above should work but in my terminal I end up getting invalid csrf token, and I am not sure why.

The CSRF token is also being used in the index.js router, by the same method, where I load it first and then directly use router.use(csrfProtection), no conditionalCSRF is being used.

It looks like the conditionalCSRF is not even getting called, when I try to use a webook, so I am not sure what is stopping it to run.

0 Answers
Related