Merge pull request #2309 from overleaf/spd-nodevcsrf

Remove /dev/csrf route from production

GitOrigin-RevId: 4dc19fa6d33214f9a4cc57ee1293c215eb072c00
This commit is contained in:
Timothée Alby
2019-11-04 16:49:48 +07:00
committed by sharelatex
parent 5112bd3696
commit df45df5b71

View File

@@ -972,7 +972,9 @@ function initialize(webRouter, privateApiRouter, publicApiRouter) {
res.send('web sharelatex is alive (api)')
)
webRouter.get('/dev/csrf', (req, res) => res.send(res.locals.csrfToken))
if (['development', 'test'].includes(process.env.NODE_ENV)) {
webRouter.get('/dev/csrf', (req, res) => res.send(res.locals.csrfToken))
}
publicApiRouter.get('/health_check', HealthCheckController.check)
privateApiRouter.get('/health_check', HealthCheckController.check)