CSRF対çã®tokenã¯ã»ãã·ã§ã³IDã§è¯ã ã»ãã¥ãªãã£çã«ã¯ã³ã¿ã¤ã ãã¼ã¯ã³>ã»ãã·ã§ã³IDã§ã¯ãªãã ã¨ãã話ãããã®è¾ºã®è¨äºã«æ¸ããã¦ãã¾ãã é«æ¨æµ©å ï¼ èªå® ã®æ¥è¨ - ã¯ãã¹ãµã¤ããªã¯ã¨ã¹ããã©ã¼ã¸ã§ãªï¼CSRFï¼ã®æ£ãã対çæ¹æ³ é«æ¨æµ©å ï¼ èªå® ã®æ¥è¨ - CSRF対çã«ãã¯ã³ã¿ã¤ã ãã¼ã¯ã³ãæ¹å¼ãæ¨å¥¨ããªãçç±, hiddenãã©ã¡ã¿ã¯æ¼ããããã®ãï¼ èã¯ããããäºã®ããã§ã tokenã¯å¤é¨ã®ãµã¤ãããç¥ãé£ã(å®è³ªç¥ãå¾ãªã)ãã®ã§ãªãã¨ãããªã ã»ãã·ã§ã³IDã¯cookieã«æ ¼ç´ããã document.cookieã¯èªãã¡ã¤ã³ã®ãã®ã¨è¦ªãã¡ã¤ã³ã®ãã®ããè¦ããªãâå¤é¨ãµã¤ãã§åããJavaScriptããã¯åç §ã§ããªã ã»ãã·ã§ã³IDã¯ãæå·å¦çã«å®å ¨ãªæ¬ä¼¼ä¹±æ°çæç³»ã§çæããã¦ããã¯ãã(å¼ç¨) æ¨æ¸¬ãäºå®ä¸ã§ããªã è£è¶³ããã¨ãã»ãã·ã§ã³IDã使ç¨ããCSRF対
{{#tags}}- {{label}}
{{/tags}}