Skip to content
This repository was archived by the owner on Dec 13, 2018. It is now read-only.
This repository was archived by the owner on Dec 13, 2018. It is now read-only.

Anti-xsrf plus opt-out for WsFed #1443

@Tratcher

Description

@Tratcher

WsFed has historically not used anti-xsrf cookies because it supports unsolicited logins. However anti-xsrf cookies could be used if there was an opt-out option for applications that required support for unsolicited logins.
#1441 (comment)

@brentschmaltz how common is it for apps to rely on unsolicited logins?

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions