3 ms·
unlikely to affect you if you're already embedding CSRF tokens in your responses, which would defeat caching anyway. Curious if this response length fiddling wi
by phpnode 13y ago
unlikely to affect you if you're already embedding CSRF tokens in your responses, which would defeat caching anyway. Curious if this response length fiddling will mitigate the attack, can anyone more knowledgeable than me confirm?
- deleted 13y ago[deleted]
- homakov 13y agointeresting point that CSRF tokens break caching. People can store it in cookie, and not put into the actual HTML.