jordi fita mas
917db31227
I use the ten first digits of the cookie’s hash, that i believe it is not a problem, has the advantage of not expiring until the user logs out, and using a per user session token is explicitly allowed by OWASP[0]. [0]: https://cheatsheetseries.owasp.org/cheatsheets/Cross-Site_Request_Forgery_Prevention_Cheat_Sheet.html#synchronizer-token-pattern |
||
---|---|---|
.. | ||
app.gohtml | ||
contacts-index.gohtml | ||
contacts-new.gohtml | ||
dashboard.gohtml | ||
form.gohtml | ||
login.gohtml | ||
profile.gohtml | ||
tax-details.gohtml | ||
web.gohtml |