I spent weeks working on a dual representation of protection on my forms. Straightup, the token storage session method does not work.
Sessions work great for refreshing the page or for those who return to history ... but a classic double gift by pressing a button several times cannot be prevented with sessions.
I think the script cannot check / record / delete sessions fast enough to catch an error when multiple clicks are processed in milliseconds from each other.
Is there any other server side way to prevent this problem?
swt83 source share