2013/11/2ã«è¡ãããé±æ«ã©ã³ãµã¼ãºã§ã®çºè¡¨è³æã§ã

å æ¥ã®ng-mtg#4 AngularJS åå¼·ä¼ã§LTãããã¨æã£ããã©ç³ãè¾¼ã¿ãéã«åããªãã£ãã®ã§ããã°ã«æ¸ãã¾ãã å æãªãªã¼ã¹ãããAngularJS 1.2ã¯ã»ãã¥ãªãã£ããã°ã£ã¦ãçãªãã¨ãèããã®ã§ãã»ãã¥ãªãã£å¨ãã®ä»çµã¿ã調ã¹ã¦ã¿ã¾ããã ãé¡ã¯ä»¥ä¸ã§ãã CSRF JSON CSP (Content Security Policy) Escaping CSRF ã¦ãã¼ã¯ãªãã¼ã¯ã³ãHTTPãªã¯ã¨ã¹ãã«è¼ãã¦ãµã¼ãã¼ã§ãã§ãã¯ãã対å¿ãä¸ã®ä¸ã§ã¯ä¸»æµï¼æè¿ã¯ã«ã¹ã¿ã ãããã®ãã§ãã¯ã«ãã対çãï¼ AngularJSã§ã¯ãXSRF-TOKEN Cookieã«ãã¼ã¯ã³ãè¼ã£ã¦ããã¨ã$httpã使ã£ãHTTPãªã¯ã¨ã¹ãã®ãããã«èªåçã«X-XSRF-TOKENãããã¼ãä»ãã XSRF-TOKEN Cookieã¯ãã¡ããNot HttpOnlyã§ã Angularçã§ã¯CS
ã©ã³ãã³ã°
ã©ã³ãã³ã°
é害
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}