Re: [friam] "Ambient capabilities"
Tony Arcieri <[email protected]>
| Newsgroups | gmane.comp.capabilities.general |
|---|---|
| Message-ID | <CAHOTMVJGrpE-KddN1NJxXJE1wL9+r7=rnB0sO1+4EixqWfn-bw@mail.gmail.com> |
On Mon, Nov 3, 2014 at 4:07 PM, Mike Stay <[email protected]> wrote: > Can an attacker predict the request? If so, he can perform a > cross-site request forgery and the browser will authenticate the > request with the cookie. > We (unfortunately) rely on backend applications to mitigate CSRF themselves. A system built entirely around Waterken/httpsy-style URLs would be great, but as an SSO system I need to integrate with "legacy" applications, much in the same way as Sandstorm. -- Tony Arcieri _______________________________________________ cap-talk mailing list [email protected] http://www.eros-os.org/mailman/listinfo/cap-talk