3 ms·
It’s secure in a “trust the client” manner. Any server code not still doing its own authentication is in for a rude awakening.
by biot 8y ago
It’s secure in a “trust the client” manner. Any server code not still doing its own authentication is in for a rude awakening.
- ec109685 8y agoIf you don’t trust the client, there is nothing you can do. An insecure browser could spoof the origin header too.
- biot 8y agoI think you’re missing my point. While you can assume well behaved clients will reduce unwanted traffic, a malicious client will spoof everything it can. Thus, there is definitely something you can do: you should never trust the client and the server should authenticate every request (as if CORS didn’t exist) instead of assuming all requests from clients are valid.