regarding security concerns, are browser providers

2019-07-30 02:06发布

Regarding security concerns, are browser-providers excusable for allowing cross-site cookies ? Does any important use of it do justify the existance of this dangerous mechanism?

See this reference

1条回答
我只想做你的唯一
2楼-- · 2019-07-30 02:49

No.

Webmasters can ask (modern) browser to only sent cookies when first-party with the SameSite attribute:

Set-Cookie: key=value; HttpOnly; SameSite=strict

https://www.sjoerdlangkemper.nl/2016/04/14/preventing-csrf-with-samesite-cookie-attribute/

Beware, it's possible that when arriving on the website from another, cookies will not be sent.

查看更多
登录 后发表回答