Skip to content

fix: preserve JSON body formatting when removing CSRF token - #10619

Open
gr8man wants to merge 1 commit into
codeigniter4:developfrom
gr8man:fix/csrf-preserve-json-body
Open

gr8man wants to merge 1 commit into
codeigniter4:developfrom
gr8man:fix/csrf-preserve-json-body

Conversation

@gr8man

@gr8man gr8man commented Oct 10, 2026

Copy link
Copy Markdown
Contributor

Description

When the CSRF token was removed from a JSON request body, the whole document was re-encoded with json_encode(), which lost the original formatting (indentation, spacing, unicode, slashes) and could alter number precision. The token is now removed from the raw body, preserving the remaining data byte-for-byte.

Checklist:

  • Securely signed commits
  • Component(s) with PHPDoc blocks, only if necessary or adds value (without duplication)
  • Unit testing, with >80% coverage
  • User guide updated
  • Conforms to style guide

@carson-codeigniter4 carson-codeigniter4 Bot added the bug Verified issues on the current code behavior or pull requests that will fix them label Oct 10, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Verified issues on the current code behavior or pull requests that will fix them

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant