æè¿ã®webã»ãã¥ãªãã£çéã§ã¯CSRFãDNS-Rebindingã話é¡ã§ãããPlackã§ã¢ããªã±ã¼ã·ã§ã³ãµã¼ããç«ã¡ä¸ããéã«ãããã®å¯¾çãã©ã®ããã«è¡ããã«ã¤ãã¦ã¾ã¨ãã¦ã¿ã¾ããã ã¾ããCSRF対çã§ãããæä½ã®Plack::Middleware::RefererCheckã使ããã¨ã«ãããRefererã®ãã§ãã¯ã«ããCSRF対çãè¡ãã¾ããCSRF対çã¨ãã¦ã¯ãonetime tokenæ¹å¼ãåå¨ãã¾ãããå人çã«ã¯Refererãã§ãã¯ãå°å ¥ã楽ã§å¥½ãã§ã¯ããã¾ããRefererãéä¿¡ããªãã¯ã©ã¤ã¢ã³ãã対象ã«ãããµã¼ãã¹ãéå¶ãããæ¹ã¯å¥éonetime tokenæ¹å¼ã®å¯¾çããããªã£ã¦ãã ããã Plack::Middleware::RefererCheckã®ä½¿ãæ¹ã¯ãã®ããã«ãªãã¾ãã(SYNOPSYSããã®æç²) use Plack::Builder; builde
{{#tags}}- {{label}}
{{/tags}}