Skip to content

Revisit the JSON only API is safe statement #9

Open
@bitinn

Description

@bitinn

I asked this in #3 but at the time I wasn't using JSON only API, so I didn't try it out.

Now that I am designing such an API, this question pops up again: it seems JSON only API is not immune from XSRF, you need at least request.type check and possibly more:

http://security.stackexchange.com/questions/10227/csrf-with-json-post

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions