Re: [RFC DRAFT] Automatic CSRF Protection
| From: | Stanislav Malyshev | Date: | Tue, 10 May 2016 04:44:59 +0000 |
| Subject: | Re: [RFC DRAFT] Automatic CSRF Protection | ||
| References: | 1 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-93139@lists.php.net to get a copy of this message | ||
Hi!
> I would like to hear from ideas/comments before I write patch for this.
> https://wiki.php.net/rfc/automatic_csrf_protection
Could you explain a bit more - when token validation happens? Where the
SESSCSRF comes from? Does this mean that every session application now
has to support URL rewrite? What happens with applications that do not
produce HTML at all, such as REST, or those that produce data further
modified by Javascript frontend?
--
Stas Malyshev
smalyshev@gmail.com