# Adding ApolloServerPluginLandingPage causes CSRF error even on localhost

**URL:** <https://community.apollographql.com/t/adding-apolloserverpluginlandingpage-causes-csrf-error-even-on-localhost/7686>\
**Category:** Server\
**Tags:** server\
**Created:** [July 6, 2024, 6:00pm UTC](https://community.apollographql.com/t/adding-apolloserverpluginlandingpage-causes-csrf-error-even-on-localhost/7686 "2024-07-06T18:00:47Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![bilabror](https://sea1.discourse-cdn.com/flex019/user_avatar/community.apollographql.com/bilabror/32/5217_2.png) [@bilabror](https://community.apollographql.com/u/bilabror)\
**Post date:** [July 6, 2024, 6:00pm UTC](https://community.apollographql.com/t/adding-apolloserverpluginlandingpage-causes-csrf-error-even-on-localhost/7686/1 "2024-07-06T18:00:47Z")

</div>

**I’m using** :

```plaintext
@apollo/server: ^4.10.4
express: ^4.19.2

```

**server code** :

```typescript
...

const app = express();
app.use(express.json());
app.use(cors());

const httpServer = http.createServer(app);

const server = new ApolloServer({
    typeDefs,
    resolvers,
    plugins: [
        ApolloServerPluginDrainHttpServer({ httpServer }),
        ApolloServerPluginLandingPageDisabled() // this is causes of CSRF error
    ],
});

await server.start();

const middleware = createMiddleware(server, { db });
app.use(rootEndpoint, middleware);

await new Promise<void>((resolve) => httpServer.listen({ port, host }, resolve));

...

```

**Fetch :**

> GET [http://localhost:4000/graphql/v1](http://localhost:4000/graphql/v1)

**Expected response :**

> Apollo’s sandbox disappears

**Actual response :**

```auto
{
  "errors": [
    {
      "message": "This operation has been blocked as a potential Cross-Site Request Forgery (CSRF). Please either specify a 'content-type' header (with a type that is not one of application/x-www-form-urlencoded, multipart/form-data, text/plain) or provide a non-empty value for one of the following headers: x-apollo-operation-name, apollo-require-preflight\n",
      "extensions": {
        "code": "BAD_REQUEST",
        "stacktrace": [
          "BadRequestError: This operation has been blocked as a potential Cross-Site Request Forgery (CSRF). Please either specify a 'content-type' header (with a type that is not one of application/x-www-form-urlencoded, multipart/form-data, text/plain) or provide a non-empty value for one of the following headers: x-apollo-operation-name, apollo-require-preflight",
          "",
          " at new GraphQLErrorWithCode (/Users/blablabla/node_modules/@apollo/server/src/internalErrorClasses.ts:15:5)",
          " at new BadRequestError (/Users/blablabla/node_modules/@apollo/server/src/internalErrorClasses.ts:116:5)",
          " at preventCsrf (/Users/blablabla/node_modules/@apollo/server/src/preventCsrf.ts:91:9)",
          " at ApolloServer.executeHTTPGraphQLRequest (/Users/blablabla/node_modules/@apollo/server/src/ApolloServer.ts:1052:20)",
          " at processTicksAndRejections (node:internal/process/task_queues:95:5)"
        ]
      }
    }
  ]
}

```
