
CVE-2023-45857の挙動を確認するデモ
Demo to verify the behavior of Axios vulnerability CVE-2023-45857
npm run dev in the app containerXSRF-TOKEN is set in the browser's developer tools
CREDENTIAL_TOKENwhoami.localhost/api has the header x-xsrf-token with the value CREDENTIAL_TOKEN