cookie ('csrftoken');. Aren't these two statements conflicting? Say there is a Cross Origin attack, then the attacker can just obtain the CSRF token from cookie ...
確定! 回上一頁