In a attempt to make the current application I\'m developing more secure, I\'ve been reading about CSRF tokens and also Nonce.
My question simply is, Are CSRF tokens
CSRF having some limitation. in case if you have requirement where you want to open any page or link in new tab then CSRF won't allow. existing token will allow to open page in new tab for 5 times only. when you will try to open 6th time it will create the new token which will not match with "server side = client side token". earlier token will expire and new token(NONCE) will create, in that case you will get 404 or 405 error.