3 ms·
I appreciate that, but in the case of TLS or CSRF tokens the server is not blindly trusting the browser in the way Sec-Fetch-Site makes it.
by louiskottmann 9mo ago
I appreciate that, but in the case of TLS or CSRF tokens the server is not blindly trusting the browser in the way Sec-Fetch-Site makes it.
- tptacek 9mo agoSure it is. The same-origin rule that holds the whole web security model together is entirely a property of browser behavior.
- louiskottmann 9mo agoThat's indeed a good example of prior full trusting of the browser by the server.