CSRF tokens vs Nonce confusion - are they the same?

后端 未结 4 2096
予麋鹿
予麋鹿 2020-12-31 05:07

In a attempt to make the current application I\'m developing more secure, I\'ve been reading about CSRF tokens and also Nonce.

My question simply is, Are CSRF tokens

4条回答
  •  半阙折子戏
    2020-12-31 05:33

    It's sort of the same thing. A "nonce" is just a one-time password itself. It can serve as cryptographic salt, but basically is just a random value. See WP:Nonce

    But to sum it up, a nonce is often used as CSRF token. It's an implementation detail. The difference to other use cases is that it later gets asserted.

提交回复
热议问题