doudu22272099831 2015-01-26 20:19
浏览 141

将CSRF令牌发送到javascript

Suppose I maintain a anti CSRF token at server side in a session

How am I supposed to pass the token to client side application if my form generation is going to be dynamic(i.e. form will be created after some action has been performed by javascript)

Is there a way to pass the token to javascript so that I can inject the token in the form.

One working way that I found is send a cookie to the browser containing the token which will be then extracted by javascript.

Any suggestions?

  • 写回答

2条回答 默认 最新

  • duanlongling5308 2015-01-26 20:26
    关注

    Sure. If you're dynamically generating the form on the client side then you're doing it from some kind of template. The token should be an argument to that creation function.

    Pass the token along to the client at request/render time and then inject it into the form as a hidden element at form generation time.

    评论

报告相同问题?

悬赏问题

  • ¥50 有数据,怎么建立模型求影响全要素生产率的因素
  • ¥50 有数据,怎么用matlab求全要素生产率
  • ¥15 TI的insta-spin例程
  • ¥15 完成下列问题完成下列问题
  • ¥15 C#算法问题, 不知道怎么处理这个数据的转换
  • ¥15 YoloV5 第三方库的版本对照问题
  • ¥15 请完成下列相关问题!
  • ¥15 drone 推送镜像时候 purge: true 推送完毕后没有删除对应的镜像,手动拷贝到服务器执行结果正确在样才能让指令自动执行成功删除对应镜像,如何解决?
  • ¥15 求daily translation(DT)偏差订正方法的代码
  • ¥15 js调用html页面需要隐藏某个按钮