CSRF 対ç㯠One Time Token ã form ãªãã«ä»ä¸ãã¦ããµã¼ãå´ã§ãã§ãã¯ããã°è¯ãã ãããããã©ã«ãã§ãµãã¼ããã¦ããã¬ã¼ã ã¯ã¼ã¯ãªã©ããããããªãã¦ãã©ã¤ãã©ãªã§ãããã§ã対å¿ã§ããã ã©ããå®å ¨ã«ã¹ãã¼ãã¬ã¹ãªãµã¼ãã¹ã¯ãªããªããªãã®ã§ããµã¼ãå´ã« redis ã memcache ãç¨æããã®ãå¥ã«å¤§å¤ãããªãã ãªã®ã§ã CSRF 対çã¨ã㦠Token ãä»ä¸ããã®ã¯ãæãå®å ¨ã§æ¨å¥¨ã§ããæ¹å¼ã§ã¯ããã ã£ã¦ããã®ãè¸ã¾ããä¸ã§ããã SameSite=Lax ããã©ã«ãã ãã©ãä»ã§ã Token å¿ é ãªã®ï¼ã¿ãããªã®ããã³ãã³è©±ã«åºãã®ã§ãããå æ¸ã¾ã¨ããã åæ ãã®è©±ã¯ãã¹ã³ã¼ããã©ããªã®ãã«ãã£ã¦è©±ãå¤å°å¤ããã®ã§ããããçµãã ä»å㯠Passive ã§ã¯ãªã Active ã«å¯¾çãã¦ããå ´åãèããã®ã§ãåæãããããã SameSite=l
{{#tags}}- {{label}}
{{/tags}}