-
against cross-site request forgery. Believe it or not, we actually already have been making use of that inside of our project. For example, I still have the post request up here from the last lesson.
-
If I go ahead and extend this out, let me go ahead and also drag this up a little bit so that we have more working room. Now, let's first take a look at the cookies.
-
You'll see our Adana session right there that holds our session information, but you also see an XSRF token here. And this is our response cookies that we're looking at right now.
-
This is the updated cookie that's coming back from our server after the fact with our response of our register to be used for the next request that we send out.
-
If we collapse down our response, we now have our request cookies where we'll also see an XSRF token being sent up with our request.
-
Now, as a caveat, you'll see some other things here like time zone that are being sent up from other projects that I have. We're using localhost 3333, so those cookies are going to get shared.
-
You won't see all of those, but really all that we're caring about in this particular lesson is the XSRF token being here. So that's being sent up with our request that Adonis is then able to use to verify the request
-
that we're sending. Furthermore, if we take a look at our headers, we scroll down, we can see the set cookie for the XSRF token inside of our response headers.
-
If we scroll down to our request headers, we also see a header for the XXSRF token, which that extra X is prefixed on there to indicate that it's a non-standard header.
-
With most AdonisJS starter kits, if we go ahead and hide our browser back away, the XSRF token is disabled by default, but because AdonisJS knows we're going to want to make
-
use of it with Inertia, it's enabled by default with the Inertia starter kit. If we jump down to our shield, this is our security configuration, you'll see that we
-
have CSP, there's our CSRF section, we also have XFrame, HSTS, content type sniffing.
-
These are all options that we can mutate to our liking to help secure our application as we see fit. Let's scroll back up here to the CSRF section.
-
This is enabled by default, and that flag that I was mentioning that's disabled by default in most starter kits is this enable XSRF cookie.
-
In the Inertia JS starter kit, this is enabled by default and set to true. This informs AdonisJS that we want an XSRF cookie to be sent down with our responses,
-
and it will update that cookie with each and every response, making sure that our XSRF value is up to date. That cookie value is then being automatically sent up with our requests because Inertia
-
JS uses Axios underneath the hood, and Axios does that automatically as well. It also sends it up as a header there too, as we saw inside of our headers.
-
So all this to say, if you're using the conventions of Inertia JS, out of the box, you won't need to worry about CSRF protection as it's already been enabled and Inertia will use it by default.
-
If however, you're using something outside the standard realms of Inertia, like the Fetch API, which is standard to browsers, then you will need to append in that cookie or header
-
information so that AdonisJS can use it to verify your CSRF and XSRF values.