Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 6790501
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 26, 20262026-05-26T17:43:57+00:00 2026-05-26T17:43:57+00:00

I am not sure whether this is a feature or a bug on the

  • 0

I am not sure whether this is a “feature” or a bug on the MVC framework.

While implementing a few actions with the [ValidateAntiForgeryToken] attribute on them I’ve noticed that although on the view, the _RequestVerificationToken hidden text field changes with every re-load of the page, the cookie _RequestVerificationToken_Lw__ always remains the same for the length of the session, i.e. all views will use the same cookie value to compare against.

From what I can gather, the value on the view is different because it gets encrypted every time but in reality, like the cookie, it’s also the same as the cookie for the length of the session.

My question is. Shouldn’t we be able to force this cookie to have a different value for every different request?

I would have thought that keeping the same cookie value for the length of the session is a security risk, as a malicious hacker could get hold of it and our CSRF (Cross Site Request Forgery) preventive measures would go out of the window.

Is there a way of forcing this cookie to get a different value for each request?

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-26T17:43:58+00:00Added an answer on May 26, 2026 at 5:43 pm

    That cookie is still part of a three pronged protection.

    They must have

    1. The cookie
    2. Your login name (hence your forms auth cookie)
    3. The anti forgery token from the page.

    With that in mind and using ssl (which you should always be using!) given the fact the tokens are NOT one time use tokens anyways, your protection level would likely not change.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

I'm not sure whether this is just a bug or an intended feature. Basically,
Not sure whether this pertains to VS 2010 or to the upgraded framework, but...
I'm not sure whether this is the origin of the bug I'm trying to
I am not sure whether this is a bug or if I have totally
I am not sure whether this only happens to me. Basically if I have
I'm not sure whether this question belongs on StackOverflow or SuperUser, but here goes
we're having this toshiba barcode printer. I'm not sure whether this problem is hardware
I'm not sure whether or not this is the appropriate way of doing this,
Just a sidenote : I'm not sure whether I should post this to serverfault
HI all, I am not sure whether this is possible in C# or in

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.