Evergreen Note
Question :: Does a CSRF cookie need to be HttpOnly such as XSRF-TOKEN cookie from Laravel.
Answer :: CSRF cookie 可以不用使用 HttpOnly flag([[internet-rfc-6265-server-requirements]]), 因為 HttpOnly flag 保護的前提下已經是被 XSS([[cross-site-scripting]]) 攻擊, 同域的狀況下 CSRF cookie 已經失去其保護作用. 而且 XSS is a much bigger hole than …
Read MorePHP7 release也一段時間了,最近在開發常會看到相關的文章,最近抽個空好好來重新學習PHP.
Read More