3 ms·
If Google required a POST to log out (as it should be, since logging someone out is changing the session state and therefore not a "safe" GET-able request[1]),
by aprescott 15y ago
If Google required a POST to log out (as it should be, since logging someone out is changing the session state and therefore not a "safe" GET-able request[1]), we could fall back to CORS as protection which removes the need for a CSRF token. Since the only way (I believe) to get a POST to fire cross-domain, without explicit user interaction through, say, a regular HTML form, is through JavaScript, the browser would refuse to make the request unless the CORS headers explicitly allowed it.
Still, using <form> buttons for logging out, consistently across the entire web, would take some effort. CSRF tokens are probably less intrusive.
[1]: http://www.w3.org/Protocols/rfc2616/rfc2616-sec9.html#sec9.1.1 http://www.w3.org/Protocols/rfc2616/rfc2616-sec9.html#sec9.1...
- nbpoole 15y ago"Since the only way (I believe) to get a POST to fire cross-domain, without explicit user interaction through, say, a regular HTML form, is through JavaScript, the browser would refuse to make the request unless the CORS headers explicitly allowed it." I'm not quite sure what you're trying to say here. But you can make cross-domain POST requests in two ways, both involving JavaScript: 1. Create an HTML form, use JavaScript to submit it. 2. Use XMLHttpRequest to make a cross-domain POST.
- aprescott 15y agoYes: "the only way [...] to get a POST to fire cross-domain [...] is through JavaScript". The request would go against the same-origin policy, at which point CORS comes into play. Edit: Ah, but creating a form in the DOM and submitting it via JavaScript... that one I hadn't thought of.
- nbpoole 15y agoTo fire automatically, yes: getting people to click on a button of their own free will is easy though.
- driverdan 15y agoCORS isn't available in all browsers. You still need additional protection for browsers that don't support it. Plus it has nothing to do with using JS to submit a form.
- aprescott 15y agoIt's certainly true that not every browser supports CORS. But thinking about it, is logging out via a cross-domain request even that necessary in the vast majority of cases? Same-origin violation would block the POST. Plus it has nothing to do with using JS to submit a form. I wasn't saying you submit a form with JavaScript, but rather that the non-JavaScript way you make a POST request is through a user-submitted form, and is therefore intended by the user as opposed to some invisible, unseen operation.