Errors
csrf-origin-rejected
A change authenticated by the session cookie did not come from the dlogify web app. Scripts must use a bearer token.
403 Forbidden · Request origin not allowed · type: https://docs.dlogify.com/errors/csrf-origin-rejected
When it happens
- A
POST,PATCH,PUTorDELETErequest authenticated only by the web session cookie came from an origin other than the dlogify web app.
How to fix it
This protects your account from cross-site requests. Scripts and other tools should not rely on the browser cookie: get a session token and send it as Authorization: Bearer <token> (see Get a session token for scripts). A request with an Authorization header is authenticated by it alone and is never subject to this check.
Example
HTTP/1.1 403 Forbidden
Content-Type: application/problem+json{
"type": "https://docs.dlogify.com/errors/csrf-origin-rejected",
"title": "Request origin not allowed",
"status": 403,
"detail": "Requests that change data with a session cookie must come from the dlogify web app.",
"instance": "req_01j…"
}