Conversation
Notices
-
Ben Kinsey (bkinsey808@identi.ca)'s status on Thursday, 02-Jun-2011 08:25:08 CEST Ben Kinsey Form tokens stop CSRF because get and post is blind: same origin policy prevents evil site from getting the form token via !ajax . !security