unable to implement crumb for csrf protection in application with api's developed using hapi and front end developed using angular 5

Viewed 233

I am getting 403 forbidden error when I access hapi endpoint protected with crumb token. I have used npm's crumb package for CSRF in my api. My Api's are developed using hapi and front end is angular 5.

I get the crumb token in the 'set-cookie' response header of my Hapi api endpoint.Crumb token is different for each end point.

How should i validate the crumb token for every request sent to my hapi endpoint through my angular application?

I have tried below approaches

  1. I have added an interceptor in my angular app and tried to extract the token using getToken method of 'HttpXsrfTokenExtractor' and set it in the 'X-XSRF-Token' header. It is throwing exception "getToken" is not a function

  2. I have added an endpoint "getCrumb" , this endpoint is returning the crumb token. I am passing this crumb token to login endpoint in the 'X-XSRF-Token' header. But this is giving me 403 forbidden error for login api.

0 Answers
Related