checkCsrf: (
sessionId: unknown,
body?: any,
) => { detail?: string; ok: boolean; reason: string } = ...
Type Declaration
-
- (
sessionId: unknown,
body?: any,
): { detail?: string; ok: boolean; reason: string }
-
Parameters
- sessionId: unknown
Optionalbody: any
Returns { detail?: string; ok: boolean; reason: string }
{ ok, reason, detail? }
Checks that a POST carries the right CSRF token for its session, compared in constant time.
A request with no session passes with
reason: 'no-session'. A refusal (missingormismatch) carries its error code.