5 ms·
For XHR, don't forget the option to do stateless CSRF protection by requiring a custom HTTP header: https://code.google.com/p/browsersec/wiki/Part2#Same-origin_
by DrewHintz 13y ago
For XHR, don't forget the option to do stateless CSRF protection by requiring a custom HTTP header: https://code.google.com/p/browsersec/wiki/Part2#Same-origin_policy_for_XMLHttpRequest https://code.google.com/p/browsersec/wiki/Part2#Same-origin_...