Conversation
Headed Network capture listed no Csrf-Token on the Contact-info navigation POST, while contained rsc-action always set csrf-token from JSESSIONID. Still require a valid ajax: JSESSIONID cookie and send it with credentials:include, but omit csrf-token on that POST only. Keep compact 398-byte emit. Document a capture-required headed click path if this still 500s. Adapter bundle 1.36.0. Co-authored-by: Cursor Agent <cursoragent@cursor.com> Co-authored-by: hraness <0thernet@users.noreply.github.com>
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
Member
Author
|
Leaving open after #245 ( |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
After adapter 1.35.0, contained Chrome still returned HTTP 500
text/htmlon the Contact-info navigation POST even with the full observed X-Li header set and the exact nested headed body (398 compact bytes). Headed Network capturePOST-request-headers-20260912.mdlisted noCsrf-Tokenrequest header, while containedrsc-actionalways setcsrf-tokenfromJSESSIONID.This PR still requires a valid
ajax:JSESSIONIDcookie and sends it withcredentials:include, but omitscsrf-tokenon that Contact-info navigation POST only. GraphQL and other contained fetches still send the header.Compact JSON emit stays. The headed Content-Length of 400 is two bytes above 398 and is not enough evidence to invent spaces or a terminator. Sec-Fetch-* and Accept-Language stay omitted until a capture proves they are required.
If this still 500s, Email may need a headed UI interaction rather than another synthetic POST: keep the bound profile document, click one reviewed Contact-info control whose identity comes from a capture, and read the SPA-issued navigation POST. That click path is documented only and stays capture-required until the exact control and issued request are reviewed. It is not implemented here.
GraphQL 403, navigation GETs, vanity HTML-shell honesty,
sduiid=screenId, the headed nested body, and observed X-Li copies stay. Soft-labels stay. Self, non-first-degree, and contradictory distances still fail closed. No email is invented.Adapter bundle 1.36.0. Plugin stays 1.6.0. Package stays 0.18.1. File inventory stays 558.
Cloud has no signed-in LinkedIn session. Do not treat this landing as live green.
Operator smoke: