- using string replacement to build the query - using wrap-json-body middleware to get requst params - temporarily disabled csrf protection