. However, this is not really needed usually since the custom header method should be good enough.
Is there something else you were looking for?
v
vivalapanda
01/09/2024, 6:15 AM
I removed the custom header from a request in curl and the request still succeeded (tried this because a pentester indicated our anti csrf wasn't fully working)
r
rp_st
01/09/2024, 7:14 AM
is that a GET request?
rp_st
01/09/2024, 7:15 AM
Cause in GET API calls, there is no csrf check thats needed.
rp_st
01/09/2024, 7:15 AM
Also, which version of the backend sdk are you using?
SuperTokens is an open source authentication solution offering features like: Different types of login: Email / password, Passwordless (OTP or Magic link based).