3 ms·
CSRF is more or less impossible in a static site architecture. Since everything is just static HTML there are generally no form submission endpoints to attack.
by mbleigh 13y ago
CSRF is more or less impossible in a static site architecture. Since everything is just static HTML there are generally no form submission endpoints to attack.
XSS can be very dangerous, as can session hijacking, but CSRF is pretty much moot on static apps.
- pygy_ 13y agoEverything is _not_ static: there's a data channel. If you need to support browsers that do not support localStorage, indexedDB or another kind of local, private storage, you must either restrict authentication to a single tab or provide a token on page load, and not later (one token per page load). This is less of a concern now, but it used to be the case.
- mbleigh 13y agoYou can use CORS and withCredentials to use simple cookie-based browser sessions for authentication. It's still hard against CSRF because as long as you properly origin-check the request you don't have to worry about form forgery. Wrote about this some at http://www.divshot.com/blog/static-apps/cookies-and-cors http://www.divshot.com/blog/static-apps/cookies-and-cors