AEM CSRF Issue / Forbidden POST Call in AEM
AEM providing CSRF Protection from 6.0 version on wards. if you are using granite.jquery dependency it will automatically provide CSRF protection framework.
if you are not using cq provided jQuery you must add granite.csrf.standalone as dependency.
if you don't want use above client libs as dependency. you can pass 'CSRF-Token' as header property for async XHR request. Call to '/libs/granite/csrf/token.json' will give 'CSRF-Token' value.
Adobe Document
if you are not using cq provided jQuery you must add granite.csrf.standalone as dependency.
if you don't want use above client libs as dependency. you can pass 'CSRF-Token' as header property for async XHR request. Call to '/libs/granite/csrf/token.json' will give 'CSRF-Token' value.
Adobe Document