Any reason to have a session id on the form?

Is there any reason to put the session id on the form as a hidden form field?


Thanks to everyone! :)

+4
source share
2 answers

This is part of one of the possible ways to prevent against attacks such as sub - forgery.

It can be used in the Synchronizer Token Template .

It can also be used in the "Double cookie sending" method mentioned at the bottom of the page linked above.

+7
source

The only reason is to maintain session state for all users, including those with cookies disabled.

+2
source

Source: https://habr.com/ru/post/1305850/


All Articles