Allow access through AJAX only not directly?

2019-09-19 08:27发布

问题:

Is there a way to only allow calls to come into a script through AJAX and not allow end users to access the page directly?

回答1:

Short answer: Nope.

Long answer: AJAX is absolutely similar to "direct" access to the url. There is literally no difference between them. Actually there is: only one header that can be forged easily



标签: ajax http