Categories
Is this a safe way to protect against csrf?
Is it possible to check with a script that the x-requested-with header equals XMLHttpRequest and only then conclude that the request is not forged?
Answer the question
In order to leave comments, you need to log in
No, of course - you can set any header when requested.
Didn't find what you were looking for?
Ask a Question
731 491 924 answers to any question