You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用app.all无法发起POST/DELETE请求仅GET可用,求排查原因

Why POST to /test Returns 404 (Lusca CSRF Middleware Issue)

Hey there, let's break down why your POST request hits a 404 while GET works perfectly, and how to fix it by skipping CSRF checks for specific routes.

First, the Root Cause

Your global Lusca CSRF middleware is the culprit here. Here's the breakdown:

  • Lusca's csrf() middleware automatically enforces CSRF token validation for non-safe HTTP methods (POST, PUT, DELETE, etc.). It skips validation for GET/HEAD/OPTIONS by default.
  • When you send a POST request to /test without including a valid CSRF token (either in the request body, headers, or cookies, depending on Lusca's config), the middleware blocks the request before it even reaches your app.all('/test') route handler. Since the request never hits your route, the server returns a 404 (as if no matching route exists for that POST endpoint).

How to Skip CSRF Checks for Specific Routes

You've got a few solid options to fix this, depending on your app's structure:

Option 1: Add a Path Check in the Global Middleware

Modify your existing global middleware to skip CSRF validation for the /test route:

app.use((req, res, next) => {
  // Bypass CSRF check for the /test route
  if (req.path === '/test') {
    return next();
  }
  // Apply CSRF validation for all other routes
  lusca.csrf()(req, res, next);
});

If you need to match multiple routes or paths with parameters, use a regex instead (e.g., if (/^\/test/.test(req.path)) to match all paths starting with /test).

Option 2: Mount CSRF Middleware Only on Protected Routes (Recommended)

Instead of applying CSRF globally, mount it only on the routes that need protection. This keeps your code cleaner and avoids conditional checks:

// First define your unprotected route (no CSRF check)
app.all('/test', function(req, res, next){ 
  console.log('hit'); 
  res.send('send') 
});

// Then mount the CSRF middleware for all subsequent routes
app.use(lusca.csrf());

// Define your protected routes (these will use CSRF validation)
app.post('/api/user', (req, res) => {
  res.send('This route is protected by CSRF');
});

Option 3: Use Lusca's Built-In Ignore Config (If Available)

Some versions of Lusca let you specify routes to ignore directly in the CSRF config. Check your Lusca version's docs, but it might look like this:

app.use(lusca({
  csrf: {
    ignoreRoutes: ['/test'] // Add routes to skip here
  }
}));

Note: This feature might vary between Lusca versions, so double-check the API for your installed version.

A Quick Security Note

Skipping CSRF checks is fine for testing or public endpoints that don't modify data, but remember: CSRF protection is critical for routes that handle user actions (like submitting forms, updating data, etc.). Only skip checks when you're sure the route doesn't need that security layer.

内容的提问来源于stack exchange,提问作者Anthony

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.25 02:28:47