Skip to content

docs: document CSRF in JSON request body limitations - #10619

Open
gr8man wants to merge 2 commits into
codeigniter4:developfrom
gr8man:fix/csrf-preserve-json-body
Open

gr8man wants to merge 2 commits into
codeigniter4:developfrom
gr8man:fix/csrf-preserve-json-body

Conversation

@gr8man

@gr8man gr8man commented Oct 10, 2026 •

Copy link
Copy Markdown
Contributor

Description

Adds a note in the CSRF documentation explaining that removing the CSRF token from a JSON object decodes and re-encodes the body (which affects formatting and may impact number precision), and recommends sending the token in the X-CSRF-TOKEN header instead if the body needs to remain intact.

Checklist:

  • Securely signed commits
  • Component(s) with PHPDoc blocks, only if necessary or adds value (without duplication)
  • Unit testing, with >80% coverage
  • User guide updated
  • Conforms to style guide

@carson-codeigniter4 carson-codeigniter4 Bot added the bug Verified issues on the current code behavior or pull requests that will fix them label Oct 10, 2026

@michalsn michalsn left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is again a good catch, but I'd stick with unset() and json_encode() here. A custom JSON scanner adds maintenance overhead and can slow processing of larger, more complex payloads. That feels like a lot to take on for fairly uncommon cases. Formatting changes like 1.10 -> 1.1 don't change the number itself.

The precision issues are real, though, so I'd document the limitation. Anyone who needs to preserve the original JSON can send the CSRF token only in the header.

Something like this should be enough for the docs:

If you include the CSRF token in a JSON object, removing it decodes and re-encodes the body. This changes its formatting and may affect number precision. To keep the JSON body unchanged, send the token in the X-CSRF-TOKEN header and leave the CSRF field out of the body.

@carson-codeigniter4 carson-codeigniter4 Bot added the documentation Pull requests for documentation only label Oct 11, 2026
@gr8man
gr8man force-pushed the fix/csrf-preserve-json-body branch from f34b1f7 to f831fad Compare October 11, 2026 19:47
@gr8man gr8man changed the title fix: preserve JSON body formatting when removing CSRF token docs: document CSRF in JSON request body limitations Oct 11, 2026
@carson-codeigniter4 carson-codeigniter4 Bot removed the bug Verified issues on the current code behavior or pull requests that will fix them label Oct 11, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Pull requests for documentation only

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants