|
|
|
|
|
by tankenmate
245 days ago
|
|
indeed, you need some form of CSRF, but the Sec-Fetch-Site is primarily focused on keeping a browser secure, not the server. Having said that it's nice defence in depth for the server as well but not strictly required as far as the server is concerned. |
|
What are you referring to when you talk about keeping the browser secure?