3 ms·
I suppose this won't work for RJS, but for other similar JSONP vulnerabilities the correct approach is probably to strip out authentication from JSONP requests
by KayEss 13y ago
I suppose this won't work for RJS, but for other similar JSONP vulnerabilities the correct approach is probably to strip out authentication from JSONP requests -- this could be done at the middleware layer or where authentication happens. Now JSONP would only leak data that you'd give to any other anonymous user.
- homakov 13y agoNot perfect though. Intranet leaks