Issues
- 7
How to use with gin?
#30 opened by dre1080 - 1
CSRF failed with bad request
#69 opened by hoang408 - 5
- 0
- 0
- 3
Combining Session and CSRF cookie
#57 opened by xeoncross - 5
How does nosurf OTP protect against BREACH?
#64 opened by xeoncross - 0
RegenerateToken generates two CSRF cookies when no previous CSRF cookie was set
#61 opened by aeneasr - 8
Validation fails with X-CSRF-Token
#7 opened by danjac - 6
Token value error
#39 opened by hellower - 1
Prevent form resubmit
#55 opened by hazcod - 1
- 5
Is this normal behavior?
#59 opened by NCSantos - 5
Cookie tokens not masked?
#16 opened by paulbellamy - 1
Remove Referer check
#46 opened by Lekensteyn - 8
SetBaseCookie not having effect
#51 opened by hazcod - 13
- 0
Wiki page for newbies doubts and problems
#52 opened by frederikhors - 2
Possible flaw
#48 opened by arjndr - 12
nosurf breaks MultipartReader()
#27 opened by bryanjeal - 8
Signing Cookies
#11 opened by elithrar - 2
Filtering out safe methods and excluded paths
#37 opened by inmylo - 3
- 4
example is insecure
#44 opened by jolan - 2
Send a response body in defaultFailureHandler
#41 opened by alexedwards - 13
Seems to be broken with Go 1.7
#35 opened by jack-chung - 2
Remove examples folder
#34 opened by alexedwards - 3
Why is the token base64 encoded?
#33 opened - 2
Broken response with nosurf and gzip middleware
#31 opened by wader - 3
- 2
Failure with enctype="multipart/form-data"
#26 opened by bryanjeal - 3
- 3
ExemptRegexps doesn't work
#23 opened by chespinoza - 3
- 3
OTP not implemented correctly.
#21 opened by james-lawrence - 3
- 2
Httprouter compatibility?
#17 opened by chespinoza - 1
- 2
Ineffective encryption
#5 opened by lukecyca - 1
Token Length
#4 opened by elithrar - 1
- 7
Employ techniques to mitigate BREACH.
#2 opened by justinas - 2
Vary: Cookie Header
#3 opened by elithrar - 1
Use only crypto/rand for token generation.
#1 opened by justinas