Error search/course_discovery/ 403 (Forbidden)

I create plugin HttpOnly for issues cookie_missing_http_only security
Session Cookie Missing ‘HttpOnly’ Attribute

This plugin

from tutor import hooks

hooks.Filters.ENV_PATCHES.add_items([
(
“openedx-lms-common-settings”,
“SESSION_COOKIE_HTTPONLY = True\nCSRF_COOKIE_HTTPONLY = True”
),
(
“openedx-cms-common-settings”,
“SESSION_COOKIE_HTTPONLY = True\nCSRF_COOKIE_HTTPONLY = True”
),
])

Error , How to fix?

https://domain/search/course_discovery/ 403 (Forbidden)
Forbidden (CSRF token missing.): /search/course_discovery/

tutor_local-lms-1 | 2026-04-01 10:48:45,464 INFO 42 [tracking] [user None] [ip 10.212.78.21] logger.py:41 - {“name”: “/search/course_discovery/”, “context”: {“user_id”: null, “path”: “/search/course_discovery/”, “course_id”: “”, “org_id”: “”, “enterprise_uuid”: “”}, “username”: “”, “session”: “”, “ip”: “10.212.78.21”, “agent”: “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36 Edg/146.0.0.0”, “host”: “lms”, “referer”: “``https://domain/courses”``, “accept_language”: “th”, “event”: “{"GET": {}, "POST": {"search_string": [""], "page_size": ["20"], "page_index": ["0"]}}”, “time”: “2026-04-01T10:48:45.464062+00:00”, “event_type”: “/search/course_discovery/”, “event_source”: “server”, “page”: null}
tutor_local-lms-1 | 2026-04-01 10:48:45,533 WARNING 42 [django.security.csrf] [user None] [ip 10.212.78.21] log.py:241 - Forbidden (CSRF token missing.): /search/course_discovery/
tutor_local-lms-1 | [pid: 42|app: 0|req: 11/132] 172.18.0.7 () {68 vars in 1427 bytes} [Wed Apr 1 10:48:45 2026] POST /search/course_discovery/ => generated 1019 bytes in 94 msecs (HTTP/1.1 403) 8 headers in 302 bytes (1 switches on core 0)
tutor_local-caddy-1 | {“level”:“error”,“ts”:1775040525.5356426,“logger”:“http.log.access.log0”,“msg”:“handled request”,“request”:{“remote_ip”:“10.101.109.2”,“remote_port”:“58932”,“client_ip”:“10.212.78.21”,“proto”:“HTTP/1.0”,“method”:“POST”,“host”:“xxx”,“uri”:“/search/course_discovery/”},“bytes_read”:40,“user_id”:“”,“duration”:0.09492327,“size”:557,“status”:403}