Skip to content

SECURITY: Is the csrf cookie enough to be safe against the CSRF attack? Shouldn't we also send a header in the call? Isn't that the CSRF point? #1525

Answered by frederikhors
frederikhors asked this question in Q&A
Discussion options

You must be logged in to vote

@aeneasr Why are you closing it? Isn't that a serious security issue?

Replies: 2 comments 13 replies

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
13 replies
@frederikhors
Comment options

@aeneasr
Comment options

@aeneasr
Comment options

@frederikhors
Comment options

@aeneasr
Comment options

Answer selected by vinckr
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants
Converted from issue

This discussion was converted from issue #1522 on July 11, 2021 11:22.