jeudi 15 janvier 2015

Other than synchronizer token, is there any way of protection against CSRF using http headers?



Recently I came across some websites using HTTP Header namely X-XSRF-Token and a cookie with similar name. Is it a better mitigation than using random token based security for CSRF?





Aucun commentaire:

Enregistrer un commentaire