ãWebAPIã®ã¹ãã¼ãã¬ã¹ãªCSRF対çãã¨ãã2011-12-04ã®è¨äºãããã¾ããã ããã§èª¬æããã¦ããCSRF対çã¯ã GETãHEADãOPTIONSã¡ã½ããã®HTTPãªã¯ã¨ã¹ãã¯CSRFä¿è·ã®å¯¾è±¡å¤ HTTPãªã¯ã¨ã¹ãã«X-Requested-Byãããããªããã°ã¨ã©ã¼ã«ãã ã¨ããé常ã«ã·ã³ãã«ãªãã®ã§ãã ããã¦ããã®å¯¾çã®åçã¨ãã¦ä»¥ä¸ã®èª¬æãããã¾ããã form, iframe, imageãªã©ããã®ãªã¯ã¨ã¹ãã§ã¯HTTPãªã¯ã¨ã¹ãã«ç¬èªã®ããããä»ä¸ãããã¨ãã§ãã¾ãããç¬èªã®ããããã¤ããã«ã¯XMLHttpRequestã使ããããªãããã§ããããã¦XMLHttpRequestã使ãå ´åã«ã¯Same Origin Policyãé©ç¨ãããããæ»æè ã®ãã¡ã¤ã³ããHTTPãªã¯ã¨ã¹ãããããã¨ã¯ãªããã¨ãããã¨ã®ããã§ãã ããã§ã XMLHttpRequestã使
{{#tags}}- {{label}}
{{/tags}}