3 ms·
Typically CSRF tokens are only required for state-changing requests - POSTs, PUTs, DELETEs. They're broadening that recommendation also to include pages that r
by sdevlin 13y ago
Typically CSRF tokens are only required for state-changing requests - POSTs, PUTs, DELETEs.
They're broadening that recommendation also to include pages that reflect input. Think GET requests that take query string parameters. So e.g. https://google.com/search?q=pajamas https://google.com/search?q=pajamas would become https://google.com/search?q=pajamas&csrf=etcetc https://google.com/search?q=pajamas&csrf=etcetc.
It seems like a pretty impractical mitigation to me. For one thing, it would make it very difficult to share links; a link containing my CSRF token wouldn't work for you. It would also make it much easier to give up your CSRF token. We would need to retrain people to think of the URLs they're viewing as personal and secret.