Event JSON
{
"id": "cc865b35b68671a7a6b02937d76b8b3724812bca1b90a54d76e21550475f0263",
"pubkey": "8ed343402c9ab3f96b13db31a354714b291ce0282425f449d6e03c9f6cce4f0c",
"created_at": 1728054719,
"kind": 1,
"tags": [
[
"e",
"068b16db22bb067f1dab1d6990d1c7af89906f232c0b32ed2a7260993f976705",
"",
"root",
"8ed343402c9ab3f96b13db31a354714b291ce0282425f449d6e03c9f6cce4f0c"
],
[
"proxy",
"https://fosstodon.org/@lil5/113249794123976945",
"web"
],
[
"e",
"e17d8c40868155637623e0dfb4addc2a65f4ba7317999e295edcf96abc770a7f",
"",
"reply",
"0b03ff7999c7a9d530dcce4c50f30a31a83d0e101494757448105afee273cd40"
],
[
"p",
"0b03ff7999c7a9d530dcce4c50f30a31a83d0e101494757448105afee273cd40"
],
[
"p",
"8ed343402c9ab3f96b13db31a354714b291ce0282425f449d6e03c9f6cce4f0c"
],
[
"proxy",
"https://fosstodon.org/users/lil5/statuses/113249794123976945",
"activitypub"
],
[
"L",
"pink.momostr"
],
[
"l",
"pink.momostr.activitypub:https://fosstodon.org/users/lil5/statuses/113249794123976945",
"pink.momostr"
],
[
"-"
]
],
"content": "cookies are inherently vulnerable to crcf attacks even if you make the cookie lifetime 30s, it gives a window where technically, a forged request elsewhere could be triggered by the user. \n\nThe options at that point is to:\n1. Shorten the crcf cookie lifetime (accept the vulnerability window)\n2. Have the crcf call return the token in the resp body the return it in the secure request as a header using JS",
"sig": "fb0e27224f80b9d47b6649354d0bcef38290ea0c5d9e2ce184970accc0920b5a357a34d847539c721cbe923c31ccc985f77c0e5604dcaf100f2132f16d22aca5"
}