Backbone and Express Forgery Protection (csrf)

août 12th, 2013

I had a problem getting Node.js/Express playing nice with Backbone. It was not sending the csrf authenticity token embedded in the page when it sent create/update/delete requests, and Express was destroying the session when it detected the invalid request.

