<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
<channel>
<title>Question2Answer Q&amp;A - Recent questions tagged token</title>
<link>https://www.question2answer.org/qa/tag/token</link>
<description>Powered by Question2Answer</description>
<item>
<title>CSRF solution about qa-caching plugin is safety?</title>
<link>https://www.question2answer.org/qa/46744/csrf-solution-about-qa-caching-plugin-is-safety</link>
<description>

&lt;p&gt;To PHP&amp;nbsp;developers:&lt;/p&gt;

&lt;p&gt;I am developing&amp;nbsp;&lt;a rel=&quot;nofollow&quot; href=&quot;http://www.question2answer.org/qa/46578&quot;&gt;caching&amp;nbsp;plugin&lt;/a&gt;&amp;nbsp;for Q2A. I have one &lt;a rel=&quot;nofollow&quot; href=&quot;http://www.question2answer.org/qa/46627&quot;&gt;big problem&lt;/a&gt; about CSRF protection. I changed&amp;nbsp;protection code on all forms on all pages&amp;nbsp;from one time token to same&amp;nbsp;session-ID (PHPSESSID)&amp;nbsp;with Javascript.&lt;/p&gt;

&lt;p&gt;My questions:&lt;/p&gt;

&lt;ol&gt;

&lt;li&gt;Do you think this measure is effective against CSRF attack?&lt;/li&gt;

&lt;li&gt;Do you know any other effective way?&lt;/li&gt;&lt;/ol&gt;

&lt;p&gt;Thank you for your cooperation.&lt;/p&gt;</description>
<category>Plugins</category>
<guid isPermaLink="true">https://www.question2answer.org/qa/46744/csrf-solution-about-qa-caching-plugin-is-safety</guid>
<pubDate>Wed, 22 Jul 2015 02:27:54 +0000</pubDate>
</item>
</channel>
</rss>