3 ms·
You're right, I was overthinking the solution. I think the most common technique I've seen for generating CSRF token is to compute an HMAC of the immutable req
by quasque 12y ago
You're right, I was overthinking the solution.
I think the most common technique I've seen for generating CSRF token is to compute an HMAC of the immutable request parameters.
I'm guessing that's what HN already implements for voting, as the token is dependent on user id and the id of the thing being voted on, and kind of looks like an SHA-1 hash.