diff --git a/services/web/app/src/router.js b/services/web/app/src/router.js index 2c248cad4c..864cae2ea1 100644 --- a/services/web/app/src/router.js +++ b/services/web/app/src/router.js @@ -972,7 +972,9 @@ function initialize(webRouter, privateApiRouter, publicApiRouter) { res.send('web sharelatex is alive (api)') ) - webRouter.get('/dev/csrf', (req, res) => res.send(res.locals.csrfToken)) + if (['development', 'test'].includes(process.env.NODE_ENV)) { + webRouter.get('/dev/csrf', (req, res) => res.send(res.locals.csrfToken)) + } publicApiRouter.get('/health_check', HealthCheckController.check) privateApiRouter.get('/health_check', HealthCheckController.check)