Can the “x-requested-with” http header be spoofed?

后端 未结 4 1775
执笔经年
执笔经年 2020-12-20 16:39

My research shows that only the Host, Referer, and User-Agent headers can be spoofed. (source)

Is this a correct assumption to make? The security of a site I am bui

4条回答
  •  半阙折子戏
    2020-12-20 17:16

    The security of a site I am building may require that "x-requested-with" cannot be faked

    Just about anything in HTTP can be spoofed. The level of 'spoofability' is hard to determine. It's fairly trivial to craft a request with any header value I desire.

    If it's your only option, so be it, but I wouldn't want to use a site that relied on it for anything important.

提交回复
热议问题