Do login forms need tokens against CSRF attacks?

前端 未结 4 1342
慢半拍i
慢半拍i 2020-11-27 10:45

From what I\'ve learned so far, the purpose of tokens is to prevent an attacker from forging a form submission.

For example, if a website had a form that input added

4条回答
  •  天命终不由人
    2020-11-27 11:02

    Yes, So other websites can't mimic your login form! As simple as that.

    What can they achieve by doing it?

    • First: you don't wanna allow that.
    • Second: Even very simple failure cases like:
      • blocking user due to incorrect password n no. of times, can be avoided.
      • Flase hacking alerts can be prevented. etc etc.

提交回复
热议问题