Delay assignment of csrftoken in Graphiql#1289
Merged
firaskafri merged 1 commit intographql-python:mainfrom Sep 24, 2022
c-py:main
Merged
Delay assignment of csrftoken in Graphiql#1289firaskafri merged 1 commit intographql-python:mainfrom c-py:main
firaskafri merged 1 commit intographql-python:mainfrom
c-py:main
Conversation
keithhackbarth
approved these changes
Jan 26, 2022
Collaborator
keithhackbarth
left a comment
There was a problem hiding this comment.
Code seems simple and well-written.
Contributor
Author
|
@keithhackbarth Do you happen to know what I should do to merge this PR? I'm not authorized to do so and the build status is still in orange. |
|
Ran into this issue, would be great if this can be merged and included in a future release! |
firaskafri
approved these changes
Sep 23, 2022
superlevure
pushed a commit
to loft-orbital/graphene-django
that referenced
this pull request
Jul 19, 2023
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The
csrftokenis currently assigned only whengraphiql.jsis first loaded.The current
csrftokencan rotated by Django, for instance when a user logs in. rotate_token performs the rotation.When this happens, the
csrftokenheld bygraphiql.jsis invalid and Graphiql will receive CSRF errors.This PR delays the assignment of the
csrftokenby moving it into thehttpClientfunction so when thecsrftokenis rotated by Django, Graphiql can pick up the new token from the cookies.