CSRF in ReactJS with Express and csurf

Viewed 1628

I'm looking for a 'nice' way to implement CSRF in ReactJS. So far I've only seen examples where it's used for SSR-apps and where they set an input type like this:

  <input type="hidden" name="_csrf" value="">

This is also possible for React, however, I don't like the fact that you have to copy it around in your codebase.

In the Express docs they talk about using it in SPA's, however, here they use the res.render (which is not used when your frontend uses ReactJS) method like so:

app.all('*', function (req, res) {
  res.cookie('XSRF-TOKEN', req.csrfToken())
  res.render('index')
})

How this be implemented in React?

0 Answers
Related