Due to improper validation of caller input, validation is silently disabled if the provided expected token is malformed, causing any user supplied token to be considered valid.
{ "imports": [ { "path": "github.com/justinas/nosurf", "symbols": [ "CSRFHandler.ServeHTTP", "VerifyToken", "verifyToken" ] } ] }