AntiForgery on .NET Core 3.1 API after 5 minutes

Viewed 112

I've just managed to setup my .NET Core 3.1 API to support antiforgery tokens to mitigate CSFR attacks by following this guide: https://www.blinkingcaret.com/2018/11/29/asp-net-core-web-api-antiforgery/

All seems to be working well from my ReactJS frontend which uses a JS API client for the first 5ish minutes after I get the antiforgery token until the token (not the cookie) seems to expire on the server and it refuses to be validated, preventing all my POST requests. A quick refresh of the antiforgery token and all is well again. I can't find any documentation online about this 5 minute timeout but it seems to be consistently doing this. Has anyone had any experience with this and how to increase the expiry time or could this be something to do with IIS hitting it's idle timeout?

0 Answers
Related