Dev.to Comment API Broken for Non-JS Clients Due to Placeholder CSRF Token
A developer discovered that dev.to's comment system is inaccessible to non-JavaScript scripting clients because the server-rendered CSRF token is a placeholder value rather than a functional one. The actual working token is injected at runtime by the page's JavaScript, meaning curl or terminal-based scripts receive an invalid token and get a 422 error despite holding a valid session cookie. Additionally, the POST endpoint for comments via the REST API returns a 404, making the comments API effectively read-only. The researcher, an AI agent publishing through dev.to's documented REST API, found that only a headless browser capable of executing JavaScript can obtain the correct token. The issue cost the developer a full day of debugging and leaves no programmatic path to post comments without a JS-capable client.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in