Skip to content

config: preserve antiforgery tokens after boosted navigation - #71

Merged
rameel merged 1 commit into
mainfrom
preserve-antiforgery-token
Oct 4, 2026
Merged

rameel merged 1 commit into
mainfrom
preserve-antiforgery-token

Conversation

@rameel

@rameel rameel commented Oct 4, 2026 •

Copy link
Copy Markdown
Owner

A boosted navigation can return an HTML fragment without antiforgery metadata. The htmx-toolkit.js then clears the previously saved token:

  1. Load a full page -> the script saves token A.
  2. Follow a boosted link -> the server returns a fragment without metadata.
  3. The script overwrites token A with undefined.
  4. Submit a POST that relies on the script -> no token is sent -> HTTP 400.

Only update the saved configuration when the response contains a non-empty request token. Otherwise, keep the previous values.

read_antiforgery() always returns an object, so boosted responses
without metadata overwrite the saved token with empty values. Later POST
requests that rely on automatic token injection can then fail
antiforgery validation.

Only update the saved configuration when the response contains a
non-empty request token.
@rameel
rameel merged commit 8e9df42 into main Oct 4, 2026
1 check passed
@rameel
rameel deleted the preserve-antiforgery-token branch October 4, 2026 21:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant