[PR #28378] fix: resolve CSRF token cookie name mismatch in browser (#28228) #32028

Closed
opened 2026-02-21 20:50:37 -05:00 by yindo · 0 comments
Owner

Original Pull Request: https://github.com/langgenius/dify/pull/28378

State: closed
Merged: Yes


Fixed issue where frontend couldn't read COOKIE_DOMAIN environment variable in browser context, causing mismatch between expected and actual CSRF cookie names (__Host-csrf_token vs csrf_token).

Changes:

  • Use getStringConfig() in web/config/index.ts to read COOKIE_DOMAIN from DOM attributes
  • Add DATA_PUBLIC_COOKIE_DOMAIN to DatasetAttr enum
  • Inject NEXT_PUBLIC_COOKIE_DOMAIN into DOM via layout.tsx datasetMap
  • Export NEXT_PUBLIC_COOKIE_DOMAIN in Docker entrypoint script

This ensures CSRF_COOKIE_NAME() returns the correct cookie name that matches what the backend sets, fixing "CSRF token is missing or invalid" errors.

🤖 Generated with Claude Code

Important

  1. Make sure you have read our contribution guidelines
  2. Ensure there is an associated issue and you have been assigned to it
  3. Use the correct syntax to link this PR: Fixes #<issue number>.

Summary

close #28228

Screenshots

Before After
... ...

Checklist

  • This change requires a documentation update, included: Dify Document
  • I understand that this PR may be closed in case there was no previous discussion or issues. (This doesn't apply to typos!)
  • I've added a test for each change that was introduced, and I tried as much as possible to make a single atomic change.
  • I've updated the documentation accordingly.
  • I ran dev/reformat(backend) and cd web && npx lint-staged(frontend) to appease the lint gods
**Original Pull Request:** https://github.com/langgenius/dify/pull/28378 **State:** closed **Merged:** Yes --- Fixed issue where frontend couldn't read COOKIE_DOMAIN environment variable in browser context, causing mismatch between expected and actual CSRF cookie names (__Host-csrf_token vs csrf_token). Changes: - Use getStringConfig() in web/config/index.ts to read COOKIE_DOMAIN from DOM attributes - Add DATA_PUBLIC_COOKIE_DOMAIN to DatasetAttr enum - Inject NEXT_PUBLIC_COOKIE_DOMAIN into DOM via layout.tsx datasetMap - Export NEXT_PUBLIC_COOKIE_DOMAIN in Docker entrypoint script This ensures CSRF_COOKIE_NAME() returns the correct cookie name that matches what the backend sets, fixing "CSRF token is missing or invalid" errors. 🤖 Generated with [Claude Code](https://claude.com/claude-code) > [!IMPORTANT] > > 1. Make sure you have read our [contribution guidelines](https://github.com/langgenius/dify/blob/main/CONTRIBUTING.md) > 1. Ensure there is an associated issue and you have been assigned to it > 1. Use the correct syntax to link this PR: `Fixes #<issue number>`. ## Summary <!-- Please include a summary of the change and which issue is fixed. Please also include relevant motivation and context. List any dependencies that are required for this change. --> close #28228 ## Screenshots | Before | After | |--------|-------| | ... | ... | ## Checklist - [ ] This change requires a documentation update, included: [Dify Document](https://github.com/langgenius/dify-docs) - [x] I understand that this PR may be closed in case there was no previous discussion or issues. (This doesn't apply to typos!) - [x] I've added a test for each change that was introduced, and I tried as much as possible to make a single atomic change. - [x] I've updated the documentation accordingly. - [x] I ran `dev/reformat`(backend) and `cd web && npx lint-staged`(frontend) to appease the lint gods
yindo added the pull-request label 2026-02-21 20:50:37 -05:00
yindo closed this issue 2026-02-21 20:50:37 -05:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: langgenius/dify#32028