Is an X-Requested-With header server check sufficient to protect against a CSRF for an ajax-driven application?

前端 未结 6 2201
庸人自扰
庸人自扰 2020-12-05 04:44

I\'m working on a completely ajax-driven application where all requests pass through what basically amounts to a main controller which, at its bare bones, looks something li

6条回答
  •  眼角桃花
    2020-12-05 05:24

    I do not think this offers any kind of protection. An attacking site could still use xmlhttprequest for its cross-site request bypass your check.

提交回复
热议问题