4 ms·
It is. I want to finally understand why and how I can secure a login form against CSRF (i.e. when I don't yet have a session for the visitor).
by xrstf 11y ago
It is. I want to finally understand why and how I can secure a login form against CSRF (i.e. when I don't yet have a session for the visitor).
- Osiris 11y agoHow we do it is a little wonky. Our web app calls GET /login which returns a CSRF cookie and an anonymous session cookie and an object that says there's no active session. The app then uses that CSRF token to POST to /login. Once the auth is successful, the anonymous session is destroyed and a new CSRF secret is generated on the authenticated session.