So, we've solved it. Spring Security sets the CSRF-Token as a cookie, which evil site example.com can't access because sites can't access ...
確定! 回上一頁