ããã«ã¡ã¯ @zaru ã§ããä»åã¯æãããã CSRF (ã¯ãã¹ãµã¤ãã»ãªã¯ã¨ã¹ãã»ãã©ã¼ã¸ã§ãª) ã®ä»æã®å¯¾çã«ã¤ãã¦ã¾ã¨ãã¦ã¿ã¾ããããããè¨äºä¸ã«ééããããã° @zaru ã¾ã§ DM ãããã¯ã¡ã³ã·ã§ã³ããã ãã (ã»ãã¥ãªãã£ã®ç´°ããé¨åã«ã¤ãã¦ã®ç解ãä¹ããâ¦) ã 2022/08/29 : 徳丸ãããããã£ã¼ãããã¯é ããå 容ãåæ ãã¾ããã徳丸ããããããã¨ããããã¾ãï¼ èªè¨¼ããã»ãªãã§å¯¾çæ¹æ³ãéãç¹ ãã¼ã¯ã³ç¢ºèªæ¹å¼ã®ãã¡ãªããã®ã¯ãã¹ãã¡ã¤ã³ã«ã¤ãã¦ã®è¨åãåé¤ã代ããã« Cookie æ¹å¤ãªã¹ã¯ãè¿½è¨ Cookie æ¹ããå¯è½æ§ã«ã¤ãã¦å¾³ä¸¸ããã®åç»ãªã³ã¯ãè¿½è¨ SameSite å±æ§ã§é²ããªãå ·ä½çãªã±ã¼ã¹ãè¿½è¨ nginx 説æãé¢ä¿ãªãã£ãã®ã§åé¤ ãããã CSRF ã£ã¦ãªã«ï¼ æããã¤ã³ã¿ã¼ãããããã£ã¦ããæ¹ã§ããã°ãã¼ãã¯ã¾ã¡ã¡ããã é¨åã¨è¨ãã°
{{#tags}}- {{label}}
{{/tags}}