Re: [RFC DRAFT] Automatic CSRF Protection

From: Date: Tue, 10 May 2016 15:32:01 +0000
Subject: Re: [RFC DRAFT] Automatic CSRF Protection
References: 1 2 3  Groups: php.internals 
Request: Send a blank email to internals+get-93151@lists.php.net to get a copy of this message
Hi! > What happens with applications that do not produce HTML at all, such as REST, > - These apps may add SESSCSRF value manually. Add where? And where that value would come from? RFC says nothing about that. -- Stas Malyshev smalyshev@gmail.com

« previous php.internals (#93151) next »