tududi/frontend/utils
Chris 6c9902b584
fix: add CSRF token support to frontend requests (#1025)
This commit implements CSRF token support for all session-based API
requests to fix the "CSRF token missing" and "CSRF token mismatch" errors
introduced after CSRF protection was added in commit 62c4cc84.

Changes:
- Created csrfService.ts utility for fetching and caching CSRF tokens
- Added getPostHeadersWithCsrf() helper to authUtils for async token injection
- Updated all service files (*Service.ts) to include CSRF tokens in POST/PUT/PATCH/DELETE requests
- Updated components with inline fetch calls to use getCsrfToken()
- Fixed CSRF middleware to use single lusca instance instead of creating new instances per request
- Improved generateToken() to use req.csrfToken() when available
- Added CalDAV path exemption to CSRF protection

Technical details:
- CSRF tokens are fetched from /api/csrf-token endpoint
- Tokens are cached and reused across requests to avoid unnecessary fetches
- Tokens are included in x-csrf-token header for state-changing requests
- Public endpoints (login, register) remain exempt from CSRF protection
- Bearer token authentication remains exempt from CSRF protection

Files modified:
- Backend: app.js, middleware/csrf.js
- Frontend: 13 service files, 8 component files
- New file: frontend/utils/csrfService.ts

This ensures all session-based requests properly include CSRF tokens while
maintaining support for API token authentication.
2026-04-14 15:06:56 +03:00
..
apiKeysService.ts fix: add CSRF token support to frontend requests (#1025) 2026-04-14 15:06:56 +03:00
areasService.ts fix: add CSRF token support to frontend requests (#1025) 2026-04-14 15:06:56 +03:00
attachmentsService.ts fix: add CSRF token support to frontend requests (#1025) 2026-04-14 15:06:56 +03:00
authUtils.ts fix: add CSRF token support to frontend requests (#1025) 2026-04-14 15:06:56 +03:00
backupService.ts fix: add CSRF token support to frontend requests (#1025) 2026-04-14 15:06:56 +03:00
bannersService.ts Fix today pagination (#596) 2025-11-26 23:00:50 +02:00
csrfService.ts fix: add CSRF token support to frontend requests (#1025) 2026-04-14 15:06:56 +03:00
dateUtils.test.ts Fix date format inconsistency in Task detail screen (#956) 2026-03-21 18:47:33 +02:00
dateUtils.ts Fix date format inconsistency in Task detail screen (#956) 2026-03-21 18:47:33 +02:00
featureFlags.ts feat: Add MCP Integration with client-agnostic instructions (#953) 2026-03-20 16:55:49 +02:00
fetcher.ts Lint frontend (#131) 2025-07-09 12:23:55 +03:00
habitsService.ts fix: add CSRF token support to frontend requests (#1025) 2026-04-14 15:06:56 +03:00
inboxService.ts fix: add CSRF token support to frontend requests (#1025) 2026-04-14 15:06:56 +03:00
keyboardShortcutsService.ts Add custom keyboard shortcuts (#749) 2025-12-28 21:58:21 +02:00
localeUtils.ts Fix date format to respect timezone preference, not just language (#898) (#916) 2026-03-06 15:44:15 +02:00
noteDeleteUtils.ts Fix notes.js & areas.js UID usage and remove IDs. (#355) 2025-09-29 16:03:46 +03:00
notesService.ts fix: add CSRF token support to frontend requests (#1025) 2026-04-14 15:06:56 +03:00
oidcService.ts fix: add CSRF token support to frontend requests (#1025) 2026-04-14 15:06:56 +03:00
profileService.ts fix: add CSRF token support to frontend requests (#1025) 2026-04-14 15:06:56 +03:00
projectsService.ts fix: add CSRF token support to frontend requests (#1025) 2026-04-14 15:06:56 +03:00
searchService.ts Reorder elements (#687) 2025-12-09 10:51:51 +02:00
sharesService.ts fix: add CSRF token support to frontend requests (#1025) 2026-04-14 15:06:56 +03:00
slugUtils.ts Setup slugify and fix nanoid issues 2025-08-08 23:14:40 +03:00
tagsService.ts fix: add CSRF token support to frontend requests (#1025) 2026-04-14 15:06:56 +03:00
taskEventService.ts Fix bump issues (#651) 2025-12-04 18:19:40 +02:00
taskIntelligenceService.ts Lint frontend (#131) 2025-07-09 12:23:55 +03:00
taskSortUtils.ts Fix in progress today priority 2025-12-14 09:07:39 +02:00
tasksService.ts fix: add CSRF token support to frontend requests (#1025) 2026-04-14 15:06:56 +03:00
timezoneUtils.ts fixup! Scaffold timezone package 2025-10-20 16:01:49 +03:00
urlService.ts fix: add CSRF token support to frontend requests (#1025) 2026-04-14 15:06:56 +03:00
userUtils.ts Tweak UI for feature 2025-10-13 11:09:19 +03:00