3 ms·
The article below seems to suggest that as long as your api is on a subdomain and is using CORS headers, you should be fine. However I’m not so sure about this
by byteshock 6y ago
The article below seems to suggest that as long as your api is on a subdomain and is using CORS headers, you should be fine.
However I’m not so sure about this, as I still implement CSRF tokens in my SPAs. (Bit of a habit from my php days) I store the tokens in local storage and pass them through the request headers.
A lot of people have different ideas and methods when it comes to CSRF protection on SPAs. I’d love to hear other people’s opinion and tactics!
Feel free to correct me on anything.
Article: https://medium.com/tresorit-engineering/modern-csrf-mitigation-in-single-page-applications-695bcb538eec https://medium.com/tresorit-engineering/modern-csrf-mitigati...