Skip to content
Discussion options

You must be logged in to vote

Ok nvm I did some more framework agnostic research and I think I understand why this is done now.

https://en.wikipedia.org/wiki/Cross-site_request_forgery#Cookie-to-header_token

Because if it just read the cookie that would ruin the point of CSRF protection.

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by ospira
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
1 participant