CSRF tokens vs Nonce confusion - are they the same?

后端 未结 4 2097
予麋鹿
予麋鹿 2020-12-31 05:07

In a attempt to make the current application I\'m developing more secure, I\'ve been reading about CSRF tokens and also Nonce.

My question simply is, Are CSRF tokens

4条回答
  •  臣服心动
    2020-12-31 05:25

    CSRF having some limitation. in case if you have requirement where you want to open any page or link in new tab then CSRF won't allow. existing token will allow to open page in new tab for 5 times only. when you will try to open 6th time it will create the new token which will not match with "server side = client side token". earlier token will expire and new token(NONCE) will create, in that case you will get 404 or 405 error.

提交回复
热议问题