*2: 管çç»é¢ã®ãã¼ã¸ãå«ã¿ã¾ã *3: ãã°ã¤ã³ã¦ã¼ã¶ã¼ã¨éãã°ã¤ã³ã¦ã¼ã¶ã¼ã両ç«ãããã«ã¯ããã£ãã·ã¥ã»ãã©ã°ã¤ã³ã®ä½¿ãæ¹ã«æ³¨æããªããã°ãªããªãã§ããã *4: CSRF æ»æã ãã§ãã°ã¤ã³ã¦ã¼ã¶ã¼ã®ç§å¯æ å ±ãæ¼æ´©ãããã¨ã¯ããã¾ããããä»ã®èå¼±æ§ã¨ã®è¤åãèããã°ã使ç¨ãã¹ããã¨æãã¾ã *5:Â å ¬éãã¼ã¸ã§ãã£ã¦ãããã°ã¤ã³ã¦ã¼ã¶ã¼å°ç¨ã®æ å ±ã表示ããå ´åã«ã¯ *4 ã¨åæ§ã使ç¨ãã¹ããã¨æãã¾ãã Ajax ã«ã¯ Ajax ã® ã»ãã¥ãªãã£ä¸ã®æ³¨æãã¹ãäºé ã夿°ããã¾ããç¹ã« XSS èå¼±æ§ ãããã¨ç§å¯æ å ±ãæ¼æ´©ãããã£ããã® CSRF 対çãå°ç¡ãã«ãªãå¯è½æ§ãããã¾ãã使ãããæèã¨ç®çã«åãããæãç®ãªãå®è£ ãã¾ããã ð ã nonceãçµã¿åãããAjaxã®å®è£ æ¹æ³ ãã£ã¨æ¬é¡ã§ã ð ããããã㯠myajax ãã©ã°ã¤ã³ã®å®è£ ãæ³å®ãã5ã¤ã®ã¹ãããã¨


{{#tags}}- {{label}}
{{/tags}}