potiuk commented on PR #28730:
URL: https://github.com/apache/airflow/pull/28730#issuecomment-1371074048

   And to add - If you grab the token, you already grabbed session as well 
because they are sent/retrieved together, so CSRF does not really protect 
against anything, because you can use session to generate CSRF token anyway.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to