Re: [friam] "Ambient capabilities"

Tony Arcieri <[email protected]>
Newsgroups gmane.comp.capabilities.general
Message-ID <CAHOTMVJGrpE-KddN1NJxXJE1wL9+r7=rnB0sO1+4EixqWfn-bw@mail.gmail.com>
On Mon, Nov 3, 2014 at 4:07 PM, Mike Stay <[email protected]> wrote:

> Can an attacker predict the request?  If so, he can perform a
> cross-site request forgery and the browser will authenticate the
> request with the cookie.
>

We (unfortunately) rely on backend applications to mitigate CSRF
themselves.

A system built entirely around Waterken/httpsy-style URLs would be great,
but as an SSO system I need to integrate with "legacy" applications, much
in the same way as Sandstorm.

-- 
Tony Arcieri

_______________________________________________
cap-talk mailing list
[email protected]
http://www.eros-os.org/mailman/listinfo/cap-talk
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.