in reply to Re: Apache2::AuthCookieDBI, Mason, and protecting against Cross-Site Request Forgery (CSRF)
in thread Apache2::AuthCookieDBI, Mason, and protecting against Cross-Site Request Forgery (CSRF)
"I don't know if any of the frameworks has automated support for this. You need an easy way to put the token parameter into every HTML form, and an easy method to check the token on every form submit, that's all."
Yes, and that's exactly what I'm seeking wisdom on. I guess I didn't make that clear? My apologies. But thanks for the advice!
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^3: Apache2::AuthCookieDBI, Mason, and protecting against Cross-Site Request Forgery (CSRF)
by tinita (Parson) on Sep 25, 2012 at 23:27 UTC |