The Chorus AWDCSRFFilter uses a custom HTTP request header named csrf_token to validate POST requests. The underscore character in the header name causes silent interoperability failures when Chorus is deployed behind proxies and load balancers that enforce HTTP header naming standards. Chorus should be enhanced to allow the token name to be modified.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.