4 ms·
> You really have to pick whether you want possible additional copies or possibly zero copies. You really don't. You can, as mentioned above, have a hidden UUI
by haikuginger 9y ago
> You really have to pick whether you want possible additional copies or possibly zero copies.
You really don't. You can, as mentioned above, have a hidden UUID field in the form that's used serverside to deduplicate submissions within a given timeframe.
- LunaSea 9y agoWouldn't you also need to regenerate CSRF tokens somehow so that the second submission doesn't reuse the initial CSRF token?
- haikuginger 9y agoDepends on how often your CSRF tokens expire. For example, Django keeps the same token for the entire session by default IIRC.
- yebyen 9y agoThat wouldn't be a successful request... if the user gets an error from your application, they know to try again. (Or more likely and more on-topic, for the offline-friendly form if the application gets the error first, the application could be smart enough to try again...) The UUID doesn't guarantee anything other than capability to prevent duplicate records from duplicate submissions. Something else has to be responsible to make sure the submission is not abandoned without user input, unless a 200 or other successful status is received.
- AgentME 9y agoThere's no reason to expire CSRF tokens after each request.
- e12e 9y agoThat's not choosing between "at least once" and "[exactly] once", but rather how to deal with "at least once".