4 ms·
I see what you mean, evil.com could still make a request that includes cookies, which is why we need CSRF tokens. But from my understanding, it wouldn't be able
by pixelperfect 7y ago
I see what you mean, evil.com could still make a request that includes cookies, which is why we need CSRF tokens. But from my understanding, it wouldn't be able to do that in a XMLHttpRequest hidden on the page. It would have to be a request from something like submitting a form which would navigate the user off the page. Is that correct? Of course it doesn't make much difference from a security perspective.
- anaphor 7y agoYou can work around that by submitting it within an invisible iframe element, e.g. https://stackoverflow.com/a/17953761/903589 https://stackoverflow.com/a/17953761/903589 But yeah, you can't just make arbitrary requests like this with XHR