Re: [RFC DRAFT] Automatic CSRF Protection

From: Date: Tue, 10 May 2016 22:58:53 +0000
Subject: Re: [RFC DRAFT] Automatic CSRF Protection
References: 1 2 3 4 5  Groups: php.internals 
Request: Send a blank email to internals+get-93179@lists.php.net to get a copy of this message
Hi! >> Add where? And where that value would come from? RFC says nothing about >> that. > > As usual. Query parameter when GET is used. Additional input when POST > is used. All users have to do is adding CSRF token to JS program. GET and POST aren't the only HTTP methods. And where JS program would get the correct token from? As far as I can see, there's no function in the RFC that produces it. -- Stas Malyshev smalyshev@gmail.com

« previous php.internals (#93179) next »