Is an X-Requested-With header server check sufficient to protect against a CSRF for an ajax-driven application?

前端 未结 6 2221
庸人自扰
庸人自扰 2020-12-05 04:44

I\'m working on a completely ajax-driven application where all requests pass through what basically amounts to a main controller which, at its bare bones, looks something li

6条回答
  •  天涯浪人
    2020-12-05 05:11

    What you are doing is secure because xmlhttprequest is usually not vulnerable to cross-site request forgery.

    As this is a client side problem, the safest way would be to check the security architecture of each browser :-)

    (This is a summary; I am adding this answer because this question is very confusing, let's see what the votes say)

提交回复
热议问题