I am getting 403 forbidden error when I access hapi endpoint protected with crumb token. I have used npm's crumb package for CSRF in my api. My Api's are developed using hapi and front end is angular 5.
I get the crumb token in the 'set-cookie' response header of my Hapi api endpoint.Crumb token is different for each end point.
How should i validate the crumb token for every request sent to my hapi endpoint through my angular application?
I have tried below approaches
I have added an interceptor in my angular app and tried to extract the token using getToken method of 'HttpXsrfTokenExtractor' and set it in the 'X-XSRF-Token' header. It is throwing exception "getToken" is not a function
I have added an endpoint "getCrumb" , this endpoint is returning the crumb token. I am passing this crumb token to login endpoint in the 'X-XSRF-Token' header. But this is giving me 403 forbidden error for login api.