2 ms·
As I understand it, the moment you’re dealing with custom scripts, you’ve left the realm of a csrf attack. They’re dependent upon session tokens in cookies
by t-writescode 10mo ago
As I understand it, the moment you’re dealing with custom scripts, you’ve left the realm of a csrf attack. They’re dependent upon session tokens in cookies
- nchmy 10mo agoCsrf is not dependent on js. It happens via normal links on external sites.
- t-writescode 10mo agoThat's what I said, yes.
- nchmy 10mo agoSorry, I misread your comment