This repository has been archived by the owner on Sep 14, 2022. It is now read-only.
Releases: expressjs/csurf
Releases · expressjs/csurf
1.11.0
- deps: [email protected]
- Add
SameSite=None
support
- Add
- deps: http-errors@~1.7.3
- deps: [email protected]
1.10.0
- deps: [email protected]
- Remove
base64-url
dependency - deps: [email protected]
- deps: [email protected]
- Remove
- deps: http-errors@~1.7.2
- Make
message
property enumerable forHttpError
s - Set constructor name when possible
- deps: depd@~1.1.2
- deps: [email protected]
- deps: [email protected]
- deps: statuses@'>= 1.5.0 < 2'
- Make
- perf: remove argument reassignment
- perf: use plain object for internal cookie options
1.9.0
- Pass invalid csrf token error to
next()
instead of throwing - Pass misconfigured error to
next()
instead of throwing - Provide misconfigured error when using cookies without cookie-parser
- deps: [email protected]
- Add
sameSite
option - Fix cookie
Max-Age
to never be a floating point number - Improve error message when
expires
is not aDate
- Throw better error for invalid argument to parse
- Throw on invalid values provided to
serialize
- perf: enable strict mode
- perf: hoist regular expression
- perf: use for loop in parse
- perf: use string concatination for serialization
- Add
- deps: csrf@~3.0.3
- Use
tsscmp
module for timing-safe token verification - deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- Use
- deps: http-errors@~1.5.0
- Add
HttpError
export, forerr instanceof createError.HttpError
- Support new code
421 Misdirected Request
- Use
setprototypeof
module to replace__proto__
setting - deps: [email protected]
- deps: statuses@'>= 1.3.0 < 2'
- perf: enable strict mode
- Add
- perf: enable strict mode
- perf: remove argument reassignment
1.8.3
- deps: [email protected]
- Slight optimizations
1.8.2
- deps: csrf@~3.0.0
- deps: uid-safe@~2.0.0
1.8.1
- deps: csrf@~2.0.7
- Fix compatibility with
crypto.DEFAULT_ENCODING
global changes
- Fix compatibility with
1.8.0
- Add
sessionKey
option
1.7.0
- Accept
CSRF-Token
andXSRF-Token
request headers - Default
cookie.path
to'/'
, if using cookies - deps: [email protected]
- deps: csrf@~2.0.6
- deps: [email protected]
- deps: uid-safe@~1.1.0
- deps: http-errors@~1.3.1
- Construct errors using defined constructors from
createError
- Fix error names that are not identifiers
- Set a meaningful
name
property on constructed errors
- Construct errors using defined constructors from