douchuang4402 2009-06-10 14:55
浏览 18
已采纳

PHP的网站安全问题? (也可能适用于ASP / Rails /等..)

Say, I have "index.htm" and "routines.php".

"index.htm" will call eventually call "routines.php" using JS (AJAX).

So, my question is, how can "routines.php" verify that the request came from the same local server and not outside? Is there a global variable I can check at PHP level or HTTP level?

Edit 1: Using AJAX

  • 写回答

6条回答 默认 最新

  • doufu2396 2009-06-10 15:08
    关注

    You may forget about the Ajax part as it's not really part of the problem. You should read about Cross Site Request Forgeries (CSRF) and CSRF tokens. Some links:

    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论
查看更多回答(5条)

报告相同问题?