RubyFlow The Ruby and Rails community linklog

CSRF protection on single page app API

Single Page application is awesome paradigm but because they communicate with APIs there is lot of confusion around what security measures are needed and what are unnecessary. In this article I’ll try to explain when is CSRF protection needed.

Post a comment

You can use basic HTML markup (e.g. <a>) or Markdown.

As you are not logged in, you will be
directed via GitHub to signup or sign in