å æ¥ã®ng-mtg#4 AngularJS åå¼·ä¼ã§LTãããã¨æã£ããã©ç³ãè¾¼ã¿ãéã«åããªãã£ãã®ã§ããã°ã«æ¸ãã¾ãã å æãªãªã¼ã¹ãããAngularJS 1.2ã¯ã»ãã¥ãªãã£ããã°ã£ã¦ãçãªãã¨ãèããã®ã§ãã»ãã¥ãªãã£å¨ãã®ä»çµã¿ã調ã¹ã¦ã¿ã¾ããã ãé¡ã¯ä»¥ä¸ã§ãã CSRF JSON CSP (Content Security Policy) Escaping CSRF ã¦ãã¼ã¯ãªãã¼ã¯ã³ãHTTPãªã¯ã¨ã¹ãã«è¼ãã¦ãµã¼ãã¼ã§ãã§ãã¯ãã対å¿ãä¸ã®ä¸ã§ã¯ä¸»æµï¼æè¿ã¯ã«ã¹ã¿ã ãããã®ãã§ãã¯ã«ãã対çãï¼ AngularJSã§ã¯ãXSRF-TOKEN Cookieã«ãã¼ã¯ã³ãè¼ã£ã¦ããã¨ã$httpã使ã£ãHTTPãªã¯ã¨ã¹ãã®ãããã«èªåçã«X-XSRF-TOKENãããã¼ãä»ãã XSRF-TOKEN Cookieã¯ãã¡ããNot HttpOnlyã§ã Angularçã§ã¯CS
{{#tags}}- {{label}}
{{/tags}}