[RFC DRAFT] Automatic CSRF Protection
| From: | Yasuo Ohgaki | Date: | Tue, 10 May 2016 03:24:29 +0000 |
| Subject: | [RFC DRAFT] Automatic CSRF Protection | ||
| Groups: | php.internals | ||
| Request: | Send a blank email to internals+get-93136@lists.php.net to get a copy of this message | ||
Hi all,
It's not nice to work on the same code (i.e. session module) for
multiple RFCs, but time is limited.
I would like to hear from ideas/comments before I write patch for this.
https://wiki.php.net/rfc/automatic_csrf_protection
Thank you for your comments.
Regards,
P.S. Precise session ID management is important, but this one is also
important. I'll finish and start voting 2 active session RFCs soon. I
may finish all of them hopefully.
--
Yasuo Ohgaki
yohgaki@ohgaki.net