Other than synchronizer token, is there any way of protection against CSRF using http headers?
Recently I came across some websites using HTTP Header namely X-XSRF-Token and a cookie with similar name. Is it a better mitigation than using random token based security for CSRF?
Aucun commentaire:
Enregistrer un commentaire