diff options
author | Niall Sheridan <nsheridan@gmail.com> | 2017-04-10 21:18:42 +0100 |
---|---|---|
committer | Niall Sheridan <nsheridan@gmail.com> | 2017-04-10 21:38:33 +0100 |
commit | 30802e07b2d84fbc213b490d3402707dffe60096 (patch) | |
tree | 934aecb8f3582325dfd1aa6652193adac87d00db /vendor/github.com/gorilla/csrf | |
parent | da7638dc112c4c106e8929601b642d2ca4596cba (diff) |
update dependencies
Diffstat (limited to 'vendor/github.com/gorilla/csrf')
-rw-r--r-- | vendor/github.com/gorilla/csrf/README.md | 2 | ||||
-rw-r--r-- | vendor/github.com/gorilla/csrf/doc.go | 4 |
2 files changed, 5 insertions, 1 deletions
diff --git a/vendor/github.com/gorilla/csrf/README.md b/vendor/github.com/gorilla/csrf/README.md index 8cad716..75e8525 100644 --- a/vendor/github.com/gorilla/csrf/README.md +++ b/vendor/github.com/gorilla/csrf/README.md @@ -1,5 +1,5 @@ # gorilla/csrf -[data:image/s3,"s3://crabby-images/fc985/fc98571c6448e2f7dae426259b030ae1bd5b4c31" alt="GoDoc"](https://godoc.org/github.com/gorilla/csrf) [data:image/s3,"s3://crabby-images/1f93a/1f93a317a1a1747ae9e786e3bdd39fbc66d55cc7" alt="Build Status"](https://travis-ci.org/gorilla/csrf) +[data:image/s3,"s3://crabby-images/fc985/fc98571c6448e2f7dae426259b030ae1bd5b4c31" alt="GoDoc"](https://godoc.org/github.com/gorilla/csrf) [data:image/s3,"s3://crabby-images/1f93a/1f93a317a1a1747ae9e786e3bdd39fbc66d55cc7" alt="Build Status"](https://travis-ci.org/gorilla/csrf) [data:image/s3,"s3://crabby-images/5ec48/5ec48021e08b2eb3c2d2611d542508348694229e" alt="Sourcegraph"](https://sourcegraph.com/github.com/gorilla/csrf?badge) gorilla/csrf is a HTTP middleware library that provides [cross-site request forgery](http://blog.codinghorror.com/preventing-csrf-and-xsrf-attacks/) (CSRF) diff --git a/vendor/github.com/gorilla/csrf/doc.go b/vendor/github.com/gorilla/csrf/doc.go index e0bf408..301abe0 100644 --- a/vendor/github.com/gorilla/csrf/doc.go +++ b/vendor/github.com/gorilla/csrf/doc.go @@ -135,6 +135,10 @@ providing a JSON API: w.Write(b) } +If you're writing a client that's supposed to mimic browser behavior, make sure to +send back the CSRF cookie (the default name is _gorilla_csrf, but this can be changed +with the CookieName Option) along with either the X-CSRF-Token header or the gorilla.csrf.Token form field. + In addition: getting CSRF protection right is important, so here's some background: * This library generates unique-per-request (masked) tokens as a mitigation |