6 ms·
But how many browsers actually send the Origin header currently? I just checked Firefox and Chrome and neither sent it on a <script> or XHR request.
by coderrr 16y ago
But how many browsers actually send the Origin header currently? I just checked Firefox and Chrome and neither sent it on a <script> or XHR request.
- nbpoole 16y agoIt definitely isn't set via <script>. I know it's sent when you make an XHR request via jQuery, so I assume you can set it as a custom header if you're rolling your own XHR.
- coderrr 16y agoAh sorry, I was only checking same domain XHRs, which doesn't seem to send the Origin header. That combined with the fact that Origin isn't sent for <script> tags seems like it can't be used to prevent CSRFs.
- nbpoole 16y agoIt might not send it automatically (I don't know, I haven't tested it), but since you're the one building the XHR, you can send the header if you want. The same origin policy won't let you see the results of a cross-domain request, so it seems like requiring the header is an effective technique. Obviously this is only true for read operations: anything that updates state would still be vulnerable to CSRF (since you don't need to be able to read the result to make the request).
- coderrr 16y agoI'm pretty sure you can't set the Origin header yourself. That would kindof defeat the purpose of it. If anything they'd only allow you to specify whether or not to include the header. But I doubt any browser even lets you do that: $.ajax({url:'http:// http:// asdf.com/1,beforeSend:function(xhr,set){xhr.setRequestHeader('Origin', 'http:// http:// realorigin.com)}}) Refused to set unsafe header "Origin" So since you can't force an Origin header to be on all of your legit API requests, you won't be able to differentiate them (using the Origin header) from an attacker with a <script> tag.
- nbpoole 16y agoI'm not seeing the same behavior you're seeing. Try using $.get instead of $.ajax? Edit: I was confusing X-Requested-With and Origin. My apologies.
- deleted 16y ago[deleted]