Skip to main content

Module origin

Module origin 

Source
Expand description

Spec section 8: every POST checks Origin. A state-changing request whose Origin (or, if a browser left that out, Referer) isn’t this app’s own origin is refused with a 403, which stops cross-site form posts even though sessions use SameSite=Lax cookies.

Functions§

check_origin