4 ms·
Most of it is installed as source files in your mvc project so you are free to change and inspect things. This is where protection against XSS/XSRF/over-posting
by varunkho 13y ago
Most of it is installed as source files in your mvc project so you are free to change and inspect things. This is where protection against XSS/XSRF/over-posting attacks is handled as in Mvc. Only the core module is delivered as closed library. But that is more of a business layer than the security layer. The best thing about the core module is that every piece is swappable (including salted password hashing with key stretching piece) as everything is based on service pattern (interfaces and contracts).
- egeozcan 13y agoThese days, it's really hard to make people trust any library that they can't see the source of, especially those that manage "sensitive stuff" like authentication.
- danabramov 13y agoI'm not at all sure it's legal but it has been trivial to view decompiled source code for any .NET class with tools like Reflector for years. If you need to see how it's done, you will see it.