From 876611de62cbc91770cdf6a05ad9b3c94cc901c3 Mon Sep 17 00:00:00 2001 From: Jamie Slome Date: Tue, 26 Mar 2024 13:19:03 +0000 Subject: [PATCH] chore: move usage of lusca csrf before serving of files with .get() --- src/service/index.js | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/service/index.js b/src/service/index.js index cfaf3dbb..c3fd4221 100644 --- a/src/service/index.js +++ b/src/service/index.js @@ -50,10 +50,10 @@ const start = async () => { app.use(express.urlencoded({ extended: true })); app.use('/', routes); app.use('/', express.static(absBuildPath)); + app.use(lusca.csrf()); app.get('/*', (req, res) => { res.sendFile(path.join(`${absBuildPath}/index.html`)); }); - app.use(lusca.csrf()); _httpServer.listen(uiPort);