Bad csrf token when making api request

(Liam McArdle) #1

I am trying to make a POST request to add a new post, however I am getting a ‘BAD CSRF’ error. My understanding is that API requests are supposed to be checked for a CSRF token if my request contains the api key. Here is my request and associated response…am I missing something?

curl -v 'http://localhost:3000' --data 'raw=This+is+the+new+body+of+the+topic&category=4&title=Sample+New+Topic' -H 'api_key:myLongAPIKey' -H 'api_username:myusername'


(Kane York) #2

api_key and api_username are POST parameters, not headers.

