Re: [RFC DRAFT] Automatic CSRF Protection
| From: | Stanislav Malyshev | Date: | Tue, 10 May 2016 22:58:53 +0000 |
| Subject: | Re: [RFC DRAFT] Automatic CSRF Protection | ||
| References: | 1 2 3 4 5 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-93179@lists.php.net to get a copy of this message | ||
Hi!
>> Add where? And where that value would come from? RFC says nothing about
>> that.
>
> As usual. Query parameter when GET is used. Additional input when POST
> is used. All users have to do is adding CSRF token to JS program.
GET and POST aren't the only HTTP methods. And where JS program would
get the correct token from? As far as I can see, there's no function in
the RFC that produces it.
--
Stas Malyshev
smalyshev@gmail.com