DEV Community

Discussion on: Using a Cookie-to-Header CSRF Token in Single Page Applications

Collapse
 
bytebodger profile image
Adam Nathaniel Davis

Much obliged. Those links are good reads. And they seem (to me) to confirm that, while the mere existence of the custom header may currently be "enough", it's probably not a bad idea to issue single-use tokens. Especially if that functionality has already been put in place.