Hi,
Our penetration testers have opened a security issue and I hope you can help us to solve it.
We need to integrate a XSRFtoken in all our Client/Server request, IDACall ones included. Is there a best practice to implement that? We use SmartGWT Power 3.0.
Maybe we can use the GWT provided classes (https://developers.google.com/web-toolkit/doc/latest/DevGuideSecurityRpcXsrf)?
Thank you!
Our penetration testers have opened a security issue and I hope you can help us to solve it.
We need to integrate a XSRFtoken in all our Client/Server request, IDACall ones included. Is there a best practice to implement that? We use SmartGWT Power 3.0.
Maybe we can use the GWT provided classes (https://developers.google.com/web-toolkit/doc/latest/DevGuideSecurityRpcXsrf)?
Thank you!
Comment