DEV Community

Discussion on: Authentication and Laravel Airlock

Collapse
 
michi profile image
Michael Z

Yes that's very true.
But what stops the attacker from retrieving a fresh csrf token using the /csrf-cookie endpoint? Are there security measures in place?

Thread Thread
 
themsaid profile image
Mohamed Said

If they gain access to the cookies then yes. The whole point is just adding more layers of security and following all recommendations and best practices.