in reply to Re: Is your web application really secure? ("CSRF")
in thread Is your web application really secure? ("CSRF")
However I regret that this takes much of the coolness and simplicity out of the concept of session cookies because they get kind of useless for POST requests.well, i think you're right, but IMHO a session cookie is most useful in GET requests, like viewing a forum thread or something else, so that you can bookmark it easily.
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^3: Is your web application really secure? ("CSRF")
by betterworld (Curate) on Apr 01, 2007 at 03:54 UTC | |
by tinita (Parson) on Apr 02, 2007 at 09:27 UTC | |
by betterworld (Curate) on Apr 03, 2007 at 15:33 UTC |