ã2021/10/15 追è¨ã ãã®è¨äºã¯æ´æ°ã忢ããã¦ãã¾ããç¾å¨ã§ã¯çè ã®ææ³ãå¤åãã¦ããé¢ãããã¾ãã®ã§ï¼éå»ã®è¨äºã¨ãã¦åèç¨åº¦ã«ã覧ãã ããã CSRFããã³ãã®å¯¾çã®ä»çµã¿ã«é¢ãã¦ã¯ãã¡ãâ ããã§å®ç§ï¼ä»ããæ¯ãè¿ã CSRF 対çã¨åä¸ãªãªã¸ã³ããªã·ã¼ã®åºç¤ - Qiita ãã®è¨äºã¯ï¼PHPã«ãããã¯ã³ã¿ã¤ã ãã¼ã¯ã³ãç¨ããå®è£ ä¾ã示ããã®ã§ããå·çæ¥ãå°ã å¤ããã®ã«ãªãã®ã§ãäºæ¿ãã ããã ã³ã¡ã³ãæ¬ã®è°è«ã«é¢ããã¾ã¨ã 以ä¸ï¼XSSèå¼±æ§ãåå¨ããªãåæï¼ãã®èå¼±æ§ãããã¨ããããCSRF対çãã»ã¨ãã©æå³ããªããªããªãã®ã§ï¼ã¾ãããããæ½°ãã¦ãããã¨ï¼ ã»ãã·ã§ã³åºå®æ»æã«å¯¾ãã対ç ãã°ã¤ã³å¾ã«session_regenerate_idãå¿ ãå®è¡ããï¼ ãã°ã¢ã¦ãå¾ã«session_destroyãå¿ ãå®è¡ããï¼ CSRFæ»æã«å¯¾ãã対ç ã»ãã·ã§ã³IDãæã

{{#tags}}- {{label}}
{{/tags}}