Here is my flow: I have an API to get the user information and I pass the CSRF token in the header to get user info. Recently i get this error Invalid CSRF.
Reason to get this error is the Drupal_get_private_key(). Private key is changed dynamically.
Here is the code that assigns the private key 'drupal_private_key' to a random value:
if (!($key = variable_get('drupal_private_key', 0))) {
$key = drupal_random_key();
variable_set('drupal_private_key', $key);
}
I checked the codes and there is no code to change this value. Could any one help me to sort this. Thanks in advance.