request.csrf_header_missing
Unsafe cookie-authenticated request without X-Transakt-CSRF: 1.
| Code | request.csrf_header_missing |
|---|---|
| HTTP status | 400 |
| Category | Validation |
| Arguments | None (args is {}) |
What the portals show
The portals translate the code, never the title. The English (en-GB) message, in ICU format with the arguments as placeholders:
The request was blocked for your security. Reload the page and try again.
Example response
{
"type": "https://docs.test.konsolutelab.uk/errors/request.csrf_header_missing",
"title": "…",
"status": 400,
"code": "request.csrf_header_missing",
"args": {},
"traceId": "00-4bf92f3577b34da6a3ce929d0e0e4736-00f067aa0ba902b7-01",
"instance": "/api/v1/…"
}Handling it
Branch on code, not on title or the status alone, and log traceId. Codes are stable; new codes may appear, so fall back on the HTTP status for a code you do not know. See Handling errors and the list of codes.