Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

That's the point of the fix: X-CSRF-Token requires the CSRF token, which is per-user, as its value. X-Requested-With, the old way of doing things, just had to be present in the request.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: