Changes

Jump to: navigation, search

Security/Origin

2 bytes added, 20:46, 14 July 2009
m
Origin header proposal for CSRF and clickjacking mitigation
<i>The HTTP Request header Sec-From, has changed from "Origin" to avoid conflict with the similarly named header in [http://www.w3.org/TR/2009/WD-cors-20090317/ Cross-Origin Resource Sharing].</i>
= Origin Sec-From header proposal for CSRF and clickjacking mitigation =
This page contains collected thoughts generated in discussion and deep thinking about implementing some type of [http://people.mozilla.org/~bsterne/content-security-policy/origin-header-proposal.html Origin-like header].
Canmove, confirm
1,537
edits

Navigation menu