Skip to content
This repository has been archived by the owner on Feb 3, 2020. It is now read-only.

csrf #10

Open
dvv opened this issue Apr 4, 2011 · 0 comments
Open

csrf #10

dvv opened this issue Apr 4, 2011 · 0 comments

Comments

@dvv
Copy link

dvv commented Apr 4, 2011

Hi!

Am I right that since the secure session cookie gets updated on every request and is definitely a nonce, it can be used also as CSRF token for free?

TIA,
--Vladimir

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant