in reply to Re^6: Perl Sessions and Cookies - Cookie don't get passed
in thread Perl Sessions and Cookies - Cookie don't get passed
Q: My web site login/logout code needs to delete cookies, how can I do this?
A: You don't do login/logout that way, it's not standard practice and what you are trying to do screams XSS attack.
Instead of deleting a cookie don't send your anti XSS hidden input.
All web forms should have some post/get variable with a secret code that only that user knows. This ensures that forms, without having the correct hidden input value, can't be submitted to the site. The site code can easily determine if the form being filled out originated from the site.
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^8: Perl Sessions and Cookies - Cookie don't get passed
by Anonymous Monk on Mar 08, 2015 at 14:01 UTC | |
by cheako (Beadle) on Mar 09, 2015 at 20:05 UTC | |
by Anonymous Monk on Mar 09, 2015 at 21:11 UTC | |
by cheako (Beadle) on Mar 10, 2015 at 00:03 UTC | |
by Anonymous Monk on Mar 10, 2015 at 00:29 UTC |