Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
dagobah
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
3 ms
·
1.
▲
by
dagobah
9y ago
I think https://en.wikipedia.org/wiki/Cross-site_request_forgery#Coo... is flawed too because "Access-Control-Allow-Origin: *" doesn't let browsers send cookies with the request, so any of the CSRF preve
2.
▲
by
dagobah
9y ago
Yea, but doing it that way requires same origin policy not to be weakened like from CORS being misconfigured. http://blog.portswigger.net/2016/10/exploiting-cors-misconfi... talks about exploits from this. But wha
3.
▲
Can “Cookie to header token” CSRF prevention be beaten with permissive CORS?
4 points
by
dagobah
9y ago
|
4 comments