isn't csrf browser confidence issue?


regarding cross-site ask forgery (csrf) attacks, cookies many used authentication method, since web browsers grant eventuality cookies domain (and domain) page generated another domain?



isn't csrf simply preventable browser disallowing such behavior?



as distant i know, kind confidence check isn't implemented web browsers, nonetheless i don't know why. i something wrong?



about csrf:








edit: i cruise cookies should sent http post above case. that's browser function surprises me.



Comments

Popular posts from this blog

list macos calm editors formula editors

how hibernate @any-related annotations?

why does floated <input> control floated component slip over too distant right ie7, nonetheless firefox?