Q
Q
Quber2015-02-22 06:48:26
PHP
Quber, 2015-02-22 06:48:26

Why is CSRF disabled/not used when working with Ajax?

I often see most examples where CSRF is not used/disabled intentionally when working with Ajax, but it is not explained why. Actually the question is why? Because it's more convenient to work with and CSRF does not create many problems, or is there no need for it? Doesn't disabling CSRF when working with Ajax reduce security, or am I wrong?

Answer the question

In order to leave comments, you need to log in

1 answer(s)
D
DevMan, 2015-02-22
@Quber

Because krivorukov and do not know how to make friends ajax and csrf-token, I see no other reason.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question