trigeek38
Server side rendered form delivered through channel csrf_token issue
I’m trying to render a form server side and deliver it over a channel. I can render the form and display it correctly but I’m getting an invalid csrf_token error when I try to post the form.
Can anyone help me troubleshoot this. I’ve tried to set the _csrf_token field to the same as the original session but I still get the same error.
Thanks,
Jeff
Trending in Questions
I’m in search of an Elixir library that offers PDF generation capabilities similar to Ruby’s Prawn. While there have been discussions abo...
New
I’m looking to build a personal workflow to quickly deploy web applications written in elixir/phoenix, for local consumption (ie not on t...
New
Using Phoenix.LiveView.TagEngine as an EEx.Engine is deprecated!
To compile HEEx, use Phoenix.LiveView.TagEngine.compile/2 instead.
Sta...
New
Hello !
We want new/edit form pages to POST/PUT to their own URL rather than the resources REST defaults (post /things, put /things/:id)...
New
Before I dive in myself, did anyone successfully sprinkle Hologram into their existing LiveView app?
Looking for hints regarding:
Addi...
New
Hi all, I wanted to ask how the community is dealing with post-release steps.
Today we have Ecto migrations, which make sure that the db...
New
I am using Oban and occasionally, shortly after a deployment, a handful of jobs can fail because of dependency on other parts of the syst...
New
Other Trending Topics
Hey, I’m Jesse and I’m the main contributor behind Dexter, a full-featured, lightning-fast Elixir LSP optimized for large codebases. It s...
New
Beam Bots (or just BB for short) is a framework for building fault-tolerant robotics applications in Elixir using familiar OTP patterns. ...
New
Hello everyone. After busy few months I am happy to announce v0.1.0 of Emerge & Solve.
They are GUI (Emerge) and State management (S...
New
Emily is an Elixir library that runs Nx computations on Apple’s MLX. Install it as the default Nx backend and Nx, defn, Axon, Nx.Serving,...
New
I just stumbled on a newly redesigned elixir-lang.org. :tada: It looks like @Software_Mansion did the work, and I think it is generally a...
New
@hugobarauna and I (Alex Koutmos) have been hard at work on writing a book on Nerves that takes you from simply blinking LEDs to building...
New
Categories:
Sub Categories:
Forums
Popular Tags
- #ecto
- #liveview
- #troubleshooting
- #learning-elixir
- #deployment
- #library
- #erlang
- #testing
- #genserver
- #mix
- #absinthe
- #remote-other
- #otp
- #plug
- #how-to-question
- #macros
- #postgres
- #channels
- #elixirconf
- #exunit
- #discussion
- #code-sync
- #javascript
- #podcasts
- #onsite
- #dialyzer
- #docker
- #authentication
- #umbrella
- #full-time-contract
- #podcasts-by-brainlid
- #ecto-query
- #elixir-ls
- #phoenix_html
- #iex
- #blog-post
- #graphql
- #genstage
- #ai
- #elixirconf-us
- #websockets
- #supervisor
- #advent-of-code
- #distillery
- #processes
- #api
- #forms
- #metaprogramming
- #performance
- #security










First Post!
OvermindDL1
Have you tried sending a new CSRF with the new form?
Also you might look at using Drab for this as its designed precisely for purposes like that.
Most Liked
peerreynders
I wonder whether this is tripping you up:
And
_csrf_tokenis simply the “unmasked” CSRF token - your particularformelement may have Phoenix looking for the token that includes the host.Edit: Looking at the source code I’m guessing you can’t use the raw
_csrf_tokenin theformelement. In the absence of the host in the URL you have to use the masked value fromPlug.CSRFProtection.get_csrf_token/0otherwise usePlug.CSRFProtection.get_csrf_token_for/1.See also: Elixir, Phoenix, CSRF tokens
trigeek38
Thanks for the reply. Yes, I tried sending a new CSRF. i think I need to do some more research and see exactly when and where it is validated and see what is’nt reconciling. Drab looks cool, but i think I’m gonna wait and see how awesome LiveView is