Skip to content

Fix login CSRF (Challenge-37): require anti-CSRF token for browser POST /login - #464

Closed
beanbeah wants to merge 4 commits into
OWASP-CTF:dc34-ctffrom
beanbeah:ctf/r2-challenge-challenge-37-csrf-login
Closed

beanbeah wants to merge 4 commits into
OWASP-CTF:dc34-ctffrom
beanbeah:ctf/r2-challenge-challenge-37-csrf-login

Fix login CSRF with a real per-session token instead of an origin check

e1013ba
Select commit
Loading
Failed to load commit list.
Sign in for the full log view

Annotations

1 warning
score
succeeded Aug 9, 2026 in 2m 4s