4 ms·
Beautiful answer, thank you! Since I want to support as many browsers as possible, I'm going to still use CSRF tokens, but a single token per session as you su
by fpereiro 7y ago
Beautiful answer, thank you!
Since I want to support as many browsers as possible, I'm going to still use CSRF tokens, but a single token per session as you suggested. I just outlined the approach here: https://news.ycombinator.com/item?id=22268152 https://news.ycombinator.com/item?id=22268152 .
Thanks for your detailed feedback, it's very valuable to me.