4 ms·
The CSRF token is generated on login and then stored in the user's session. We accept the risk of not having a per-form token for pure developer/user convenienc
by xrstf 11y ago
The CSRF token is generated on login and then stored in the user's session. We accept the risk of not having a per-form token for pure developer/user convenience reasons.
- amenghra 11y agoThis is exactly what the parent suggests doing. Keep in mind that if you don't change the client's view of the token on every page load (using some kind of salt), you are potentially vulnerable to CRIME/BEAST.