XMLHttpRequestã使ã£ãCSRF対ç - èã£ã±æ¥è¨ãæ¸ãã¦ãã¦æã£ããã©ããã¾ãã¡XHRã使ã£ãCSRF(ã¨ãããã¯ãã¹ãªãªã¸ã³éä¿¡)ã«ã¤ãã¦ç解ããã¦ããªããããªæãã ã£ãã®ã§ãã¡ãã£ã¨æ¸ãã¦ããã¾ããã¨ããããæ¥æ¬èªã®ãªã½ã¼ã¹çã«ã¯ãHTTP access control | MDN ã詳ããã¦ããããèªãã°ã ãããäºè¶³ãããã§ããã¨ã¯CSRFã«é¢é£ããããªè©±é¡ã ãã Q. ãããããã¯ãã¹ãªãªã¸ã³ãã£ã¦ä½ï¼ ã¹ãã¼ã ããã¹ãããã¼ãã®3ã¤ã®çµã¿åãããä¸è´ãã¦ããå ´åãåä¸ãªãªã¸ã³(same-origin)ãããããä¸ã¤ã§ããã¨ãªãå ´åãã¯ãã¹ãªãªã¸ã³(cross-origin)ã¨è¨ãã¾ããã¤ã¾ããXHRã§ãã¡ã¤ã³ãè¶ ãã¦éä¿¡ãã¦ããå ´åã¯å ¸åçãªã¯ãã¹ãªãªã¸ã³éä¿¡ã¨ãªãã¾ãã Q. ãï¼ XMLHttpReuest ã£ã¦ä»ã®ãã¡ã¤ã³ã«ãªã¯ã¨ã¹ããçºè¡ã§ããªãããã ã
{{#tags}}- {{label}}
{{/tags}}