3 ms·
Just a word of warning, since the article doesn't make it clear: Using POST is not an effective defense against CSRF. You need to include some sort of unique
by asdfjqer 18y ago
Just a word of warning, since the article doesn't make it clear: Using POST is not an effective defense against CSRF. You need to include some sort of unique token in the form.
(Checking the referrer certainly helps, but will cause problems for anyone who has referrers disabled in browser privacy settings or is behind a proxy that strips referrer headers)