RubyFlow The Ruby and Rails community linklog

Rails API CSRF protection for SPA

How to secure Rails API for SPA with CSRF protection? Is it needed for JWT ? Or just for session cookies? In this article we will look at the problems and solutions :)

https://blog.eq8.eu/article/rails-api-authentication-with-spa-csrf-tokens.html

Post a comment

You can use basic HTML markup (e.g. <a>) or Markdown.

As you are not logged in, you will be
directed via GitHub to signup or sign in