Minor Changes
-
BREAKING CHANGE:
csrf()now reads submitted tokens from headers and parsed form fields only by default. Requests that supply a token only in the query string are rejected. Applications that need query parameter tokens can retain that behavior with an explicitvalueresolver, which replaces the default lookup:-csrf() +csrf({ + value(context) { + return context.url.searchParams.get('_csrf') + }, +})
Patch Changes
-
Declare package modules as side-effect-free.
-
Bumped
@remix-run/*dependencies: