4 ms·
Why would this not work: a) Resources using something other than GET are automatically not affected. b) For GET resources, require that the body of the reques
by thadeus_venture 15y ago
Why would this not work:
a) Resources using something other than GET are automatically not affected.
b) For GET resources, require that the body of the request contains a value, perhaps from a cookie but could be anything, ensuring that the request was made using xhr, which is domain restricted.
Sounds like the simplest way to me, curious why it wouldn't work.
- ww520 15y agoGood thought. The "double-submitted cookie" technique does exactly that.
- rachelbythebay 15y agoPoint A sounds perfect to me. Why bother with GET at all? For point B, I notice that I get an "x-requested-with: XMLHttpRequest" when doing ajax() from inside jQuery. I assume this is not there when someone SCRIPT SRCs something (why would it be?), so that may be useful to someone.