CSRF token in page source

前端 未结 0 1681
执念已碎
执念已碎 2020-12-02 23:36

If the token is visible in the page source (I.e. hidden input field) wouldn’t this defeat the purpose? The token can just be grabbed from the page source. Maybe I’m overthin

相关标签:
回答
  • 消灭零回复
提交回复
热议问题