Does setting cookies 'SameSite=none; Secure' and providing CSRF-TOKEN suffice to prevent CSRF in embeddable web application?

后端 未结 0 1770
悲哀的现实
悲哀的现实 2021-01-31 20:09

My web application (myApp further) is embedded in iframe of a single third-party webpage. MyApp sets cookie Set-Cookie: JSESSIONID=38FE580EE7D8CACA581532DD37A19182; Path=/

相关标签:
回答
  • 消灭零回复
提交回复
热议问题