PHP check to make sure request is either xmlhttp from my site or normal request from a certain domain

前端 未结 4 415
心在旅途
心在旅途 2020-12-22 07:13

How would the condition be written to ensure a page is either accessed by xmlhttp request from my site or from an allowed outside domain?



        
4条回答
  •  暗喜
    暗喜 (楼主)
    2020-12-22 08:02

    You need to be aware that HTTP headers are easily spoofed so someone could easily telnet and send that HTTP header and access the page. Do not rely upon HTTP REFERER for sensitive data. The only reasonably safe prevention is to use logins.

提交回复
热议问题