F
F
Fivebam2020-07-18 11:34:20
CSRF
Fivebam, 2020-07-18 11:34:20

Is this a safe way to protect against csrf?

Is it possible to check with a script that the x-requested-with header equals XMLHttpRequest and only then conclude that the request is not forged?

Answer the question

In order to leave comments, you need to log in

1 answer(s)
A
Alexey Ukolov, 2020-07-18
@Fivebam

No, of course - you can set any header when requested.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question