Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I've dealt with backends that refresh a CSRF token on each valid request and return it in the response as a cookie. In those cases a solution like this may be needed. Not optimal but, we don't always have control over the backends we use, especially then they're provided by a third party.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: