diff --git a/Contestation/verify_facial_api.php b/Contestation/verify_facial_api.php
index c43d281..955ef42 100644
--- a/Contestation/verify_facial_api.php
+++ b/Contestation/verify_facial_api.php
@@ -234,13 +234,20 @@ if ($_SERVER['REQUEST_METHOD'] === 'POST') {
$input = json_decode(file_get_contents('php://input'), true);
$csrf_token = $input['csrf_token'] ?? null;
-
- var_dump(
- array(
- "csrf_token" => $csrf_token,
- )
- );
+ if (!isset($csrf_token)) {
+ echo json_encode(['success' => false, 'message' => 'Mauvaise session! Absence']);
+ exit;
+ }
+
+ if (!Csrf::validateToken($csrf_token)) {
+ echo json_encode(['success' => false, 'message' => 'Mauvaise session! No much']);
+ exit;
+ }
+
+ echo json_encode(['success' => false, 'message' => 'On peut maintenant continuer']);
+ exit;
+
$action = $input['action'] ?? null;
$api = new FacialVerificationAPI();