3 ms·
Don't have access to the headers from JS. Best solution might be to generate a short-lived one-time-use ticket and pass it in the querystring.
by latch 5y ago
Don't have access to the headers from JS.
Best solution might be to generate a short-lived one-time-use ticket and pass it in the querystring.
- simonkagedal 5y agoCookies will be forwarded though, or..?
- twic 5y agoIf you make a normal HTTP request first, the server can issue a standard HTTP cookie to the client. That cookie will then be included when the browser makes the websocket request. However, websockets are not subject to the same-origin policy, so this exposes you to CSRF [1]. To protect against that, you should check the Origin header on the server side. [1] https://christian-schneider.net/CrossSiteWebSocketHijacking.html https://christian-schneider.net/CrossSiteWebSocketHijacking....