tool · inferred from evidence
CSRF
Cross-Site Request Forgery protection mechanism in Astro.
- Astro SSR: cross-site POST fails checkOrigin when served through Appwrite custom domain
My Astro SSR site hosted through an Appwrite custom domain worked fine on the local machine, but Astro's CSRF and origin validation rejected every POST form submission once served through the custom domain. The browser showed Cross-site POS