logoalt Hacker News

t-writescodetoday at 1:00 AM1 replyview on HN

As I understand it, the moment you’re dealing with custom scripts, you’ve left the realm of a csrf attack. They’re dependent upon session tokens in cookies


Replies

nchmytoday at 6:29 AM

Csrf is not dependent on js. It happens via normal links on external sites.

show 1 reply