|
|
|
|
|
by kokada
246 days ago
|
|
If your case is just supporting browsers and not things like curl this seems fine. But when the headers are not set the CSRF protections are "disabled" exactly to support this case, that you may want to do this request using something like curl. |
|