4 ms·
Again, we believe that sessions and CSRF protection can be orthangonal (and that there are benefits to doing so). If you can prove otherwise, let us know! Ther
by jacobian 13y ago
Again, we believe that sessions and CSRF protection can be orthangonal (and that there are benefits to doing so). If you can prove otherwise, let us know!
There's also https://github.com/mozilla/django-session-csrf https://github.com/mozilla/django-session-csrf, an alternate CSRF implementation by Mozilla that does use session-linked CSRF tokens. So if you insist on "tokens must be session-linked", you can use that instead.
- homakov 13y agosorry, I think in terms of Rails, in rails a session is a _site_sess cookie... i am not sure how it works in Django but what here is a post about it http://homakov.blogspot.com/2013/06/cookie-forcing-protection-made-easy.html http://homakov.blogspot.com/2013/06/cookie-forcing-protectio... https://github.com/mozilla/django-session-csrf https://github.com/mozilla/django-session-csrf seems ok, should be default
- JshWright 13y ago"i am not sure how it works in Django" Perhaps you should do a little research before proclaiming things insecure?
- homakov 13y agobitbucket is vulnerable > django has a problem if it's not enough: some websites from http://www.djangosites.org/ http://www.djangosites.org/ are vulnerable > django has a problem
- homakov 13y agoand yes, they clearly state it was made as a solution to cookie forcing: >Your site is on a subdomain with other sites that are not under your control, so cookies could come from anywhere. it should be default, for sure.