@@ -403,10 +403,10 @@ def test_headers(self):
403
403
refresh_csrf = resp .headers [4 ][1 ]
404
404
self .assertIn ('access_token_cookie' , access_cookie )
405
405
self .assertIn ('csrf_access_token' , access_csrf )
406
- self .assertIn ('Path=/api/ ' , access_csrf )
406
+ self .assertIn ('Path=/' , access_csrf )
407
407
self .assertIn ('refresh_token_cookie' , refresh_cookie )
408
408
self .assertIn ('csrf_refresh_token' , refresh_csrf )
409
- self .assertIn ('Path=/auth/refresh ' , refresh_csrf )
409
+ self .assertIn ('Path=/' , refresh_csrf )
410
410
411
411
# Try with overwritten options
412
412
self .app .config ['JWT_ACCESS_COOKIE_NAME' ] = 'new_access_cookie'
@@ -423,10 +423,10 @@ def test_headers(self):
423
423
refresh_csrf = resp .headers [4 ][1 ]
424
424
self .assertIn ('new_access_cookie' , access_cookie )
425
425
self .assertIn ('x_csrf_access_token' , access_csrf )
426
- self .assertNotIn ('Path=/' , access_csrf )
426
+ self .assertIn ('Path=/' , access_csrf )
427
427
self .assertIn ('new_refresh_cookie' , refresh_cookie )
428
428
self .assertIn ('x_csrf_refresh_token' , refresh_csrf )
429
- self .assertNotIn ('Path=/' , refresh_csrf )
429
+ self .assertIn ('Path=/' , refresh_csrf )
430
430
431
431
def test_endpoints_with_cookies (self ):
432
432
self .app .config ['JWT_COOKIE_CSRF_PROTECT' ] = False
0 commit comments