Issues
- 0
How to pass csrf token to client which use httpclient to call the restful api
#23 opened by wushuaizaiza - 1
[Discussion] About securing the "secret" in cookie
#19 opened by 4auvar - 0
- 8
Revisit the JSON only API is safe statement
#9 opened by bitinn - 3
Confusion over > "Unfortunately, this does not block the above request as it does not use JavaScript (so CORS is not applicable)."
#15 opened by igauravsehrawat - 14
What's the attack vector on /csrf?
#6 opened by marfire - 3
Add origin header checking
#13 opened by g-k - 0
inaccurate translation
#16 opened by RyanChill94 - 4
Get the CSRF through simulated client
#7 opened by idf - 0
Add samesite cookies
#14 opened by g-k - 2
Saying that GET should have no side effects is glossing over what is happening
#12 opened by hurricane766 - 2
Improper use of "idempotent"
#5 opened by marfire - 4
Passing CSRF token to client
#3 opened by bitinn - 13
Older browser clause
#2 opened by bitinn