diff --git a/CHANGELOG.md b/CHANGELOG.md index 6b41101576..43a9ba5d50 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -10,6 +10,8 @@ ### Fixes +* Specify the content type when calling back to Astro with JSON to render an area. This is required starting in Astro 4.9.0 and up, otherwise the request is blocked by CSRF protection. + ## 4.23.0 (2025-10-30) ### Adds diff --git a/modules/@apostrophecms/area/index.js b/modules/@apostrophecms/area/index.js index e72695a6f7..ca10c429bc 100644 --- a/modules/@apostrophecms/area/index.js +++ b/modules/@apostrophecms/area/index.js @@ -376,7 +376,9 @@ module.exports = { const response = await fetch(`${self.apos.baseUrl}/api/apos-external-front/render-area`, { method: 'POST', headers: { - 'apos-external-front-key': self.apos.externalFrontKey + 'apos-external-front-key': self.apos.externalFrontKey, + // Without this Astro enforces CSRF protection starting in version 4.9.0 + 'content-type': 'application/json' }, body: JSON.stringify({ area