4 ms·
you are correct it could be theoretically pressed by someone else, but it should be really difficult because of the unpredictability of IDs. It should be simple
by dddomodossola 8y ago
you are correct it could be theoretically pressed by someone else, but it should be really difficult because of the unpredictability of IDs. It should be simpler to attack flask or django based webinterfaces. doesn't it?
- swinglock 8y agoUnpredictability is an inconvenience. Django and Flask does feature reliable protection. https://docs.djangoproject.com/en/stable/ref/csrf/ https://docs.djangoproject.com/en/stable/ref/csrf/ https://flask-wtf.readthedocs.io/en/stable/csrf.html https://flask-wtf.readthedocs.io/en/stable/csrf.html