It is more robust than referrer checking and a nice addition to tokens. http://seclab.stanford.edu/websec/csrf/csrf.pdf (proposed here) https://wiki.mozilla.org/Security/Origin
It is more robust than referrer checking and a nice addition to tokens.
http://seclab.stanford.edu/websec/csrf/csrf.pdf (proposed here)
https://wiki.mozilla.org/Security/Origin