浏览代码

Disable sessions & CSRF verification for the /up route - Fixes #458

Bubka 4 月之前
父节点
当前提交
fc7ca1448c
共有 1 个文件被更改,包括 4 次插入0 次删除
  1. 4 0
      routes/web.php

+ 4 - 0
routes/web.php

@@ -17,7 +17,9 @@ use App\Http\Controllers\SystemController;
 use App\Http\Middleware\AddContentSecurityPolicyHeaders;
 use App\Http\Middleware\CustomCreateFreshApiToken;
 use App\Http\Middleware\SetLanguage;
+use App\Http\Middleware\VerifyCsrfToken;
 use Illuminate\Routing\Middleware\SubstituteBindings;
+use Illuminate\Session\Middleware\StartSession;
 // use Illuminate\Foundation\Events\DiagnosingHealth;
 // use Illuminate\Support\Facades\Event;
 use Illuminate\Support\Facades\Route;
@@ -100,6 +102,8 @@ Route::get('refresh-csrf', function () {
 });
 
 Route::withoutMiddleware([
+    StartSession::class,
+    VerifyCsrfToken::class,
     SubstituteBindings::class,
     SetLanguage::class,
     CustomCreateFreshApiToken::class,