-
-
Notifications
You must be signed in to change notification settings - Fork 220
per-page CSRF token support #120
Comments
The token is validated against the visitor's session or csrf cookie. |
I didn't put any option on the |
Sorry, I guess it submitted my "first draft". Here is what I meant to post: The token is validated against the visitor's session or csrf cookie. This means that the token is valid for the entire life time (in your case the life of the session). For most use-cases this is good enough, since the main protection is to guard against another origin with the same user's web browser making a cross-origin request (it won't know the token). The token is different for each If there is a desire to create per-page tokens, that shouldn't be too difficult to add in, so PRs welcome! |
Thanks for the information and explanation. For the meantime i will limit the token to the page that was required. I will try to check if i can add a create per-page token. I'm thinking if we can add option to path on the token and path from on the request params. |
By the way i'm just new on here what do you mean about this "PRs welcome!" . Sorry very noob question . Thanks |
Hi @francisfernando sorry, PR = pull request https://help.github.com/articles/about-pull-requests/ |
Thanks. Happy to help . I will review on how i can help. The issue per page you cannot determine where the call have been perform(which page). Do you have any idea how we can check this in express js or node? |
@federomero not off-hand, which is why I was hoping for some help :) |
I gave this a try - fluxsauce@7d0ef69 - and it worked within a very limited set of circumstances. If you are performing multiple POSTs on a page, such a tracking event followed by a form submission, something will fail. If you open up two browser windows, both with login forms, one of those login forms will be broken. Kind of on the "not worth it" side of the fence right now :-( |
Currently we implement the CSURF in our project to add security feature.
Here how we implement it :
under routes
Add the token in meta data
<meta name="csrf-token" content="{{_csrftoken}}">
Then override AJAX to add the token
Then i try the a single token in all the page and it was working. It should be valid only in one page or one request ?
The text was updated successfully, but these errors were encountered: