Skip to content

fix: preserve JSON request body when CSRF token is not in it - #10620

Open
gr8man wants to merge 1 commit into
codeigniter4:developfrom
gr8man:fix/csrf-json-nonobject-body
Open

gr8man wants to merge 1 commit into
codeigniter4:developfrom
gr8man:fix/csrf-json-nonobject-body

Conversation

@gr8man

@gr8man gr8man commented Oct 10, 2026

Copy link
Copy Markdown
Contributor

Description

When the CSRF token was sent via the X-CSRF-TOKEN header and the request body was valid JSON that is not an object (e.g. a JSON array), removeTokenInRequest() fell through to the form-encoded branch and rewrote the body into a URL-encoded string ([{"foo":"bar"}] became empty, 123 became 123=). A valid JSON body that is not an object is now left untouched.

Checklist:

  • Securely signed commits
  • Component(s) with PHPDoc blocks, only if necessary or adds value (without duplication)
  • Unit testing, with >80% coverage
  • User guide updated
  • Conforms to style guide

@carson-codeigniter4 carson-codeigniter4 Bot added the bug Verified issues on the current code behavior or pull requests that will fix them label Oct 10, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Verified issues on the current code behavior or pull requests that will fix them

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant