Repository navigation
feat(flow): expose received cookies to templates for CSRF - #61
Merged
Merged
Conversation
Double-submit CSRF protection has the client copy a cookie into a header
(X-CSRFToken, X-XSRF-TOKEN). A flow could keep a cookie session (the client
has a jar) but had no way to read a cookie's value, so such requests always
failed with 403.
- httpclient.New uses a recording jar that also keeps the latest value of
every cookie it receives, URL-decoded; httpclient.Cookies reads them.
- Request and GraphQL nodes add them as the `cookies` variable:
{{ cookies.csrftoken }} / {{ cookies["XSRF-TOKEN"] }}. A flow variable
named cookies wins.
Claude-Session: https://claude.ai/code/session_01DTfHLHkkg1TPGQgj6P6grg
Contributor
📊 Performance ComparisonGenerated on 2026-10-07 16:07:13 UTC Detailed Results
📈 Summary Statistics
✅ Stable Performance: All benchmarks within acceptable range |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Double-submit CSRF protection (Django
csrftoken, Laravel and AngularXSRF-TOKEN, many Express apps) has the client copy a cookie into a header. Flows already kept cookie sessions through the client's jar, but couldn't read a cookie's value, so such requests always got 403.httpclient.Newuses a recording jar that also keeps the latest value of every cookie it receives, URL-decoded the way client code reads them.httpclient.Cookiesreturns them.cookiesvariable:{{ cookies.csrftoken }}/{{ cookies["XSRF-TOKEN"] }}. A flow variable namedcookiestakes precedence.cli: minor.Verified
WithCookies.X-CSRF-Token: {{ cookies.csrftoken }}. 4/4 steps pass, in both template forms. It got 403 before.server:lint,cli:lint,root:lint:format,client:lint,server:testgreen.cli:test: only the knownTestFlowRun_WebSocketflake failed. Measured over 20 runs each, it fails 4/20 on this branch and 5/20 on main.🤖 Generated with Claude Code
https://claude.ai/code/session_01DTfHLHkkg1TPGQgj6P6grg