2 ms·
It's not the same but aren't the httpOnly cookies kind of serve the same purpose? JS can't read these cookies at all?
by blntechie 9y ago
It's not the same but aren't the httpOnly cookies kind of serve the same purpose? JS can't read these cookies at all?
- hdhzy 9y agoJS can't (that protects against stealing the token) but the server still receives it even when the request originates from foreign domain. That's the gist of CSRF [0]. [0]: https://en.wikipedia.org/wiki/Cross-site_request_forgery https://en.wikipedia.org/wiki/Cross-site_request_forgery