Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 6253385
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 24, 20262026-05-24T13:59:02+00:00 2026-05-24T13:59:02+00:00

Many sources suggest to add tokens to the forms to make form submitting more

  • 0

Many sources suggest to add tokens to the forms to make form submitting more secure.

I added tokens to all forms in the forum and now I have the following problem:

some users open several browser tabs with different forum threads. Reply form is located below each thread. So, if user opens one browser tab with one thread, then another tab with another thread, the token in the first form is not valid anymore and user will get error if will try to submit the first form. Solution for such situations is captcha but I don’t want to make everything so complicated for my users.

Can you suggest any other method how to add security to the forms?

Thanks.

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-24T13:59:03+00:00Added an answer on May 24, 2026 at 1:59 pm

    Why is the token invalidated when opening a new tab? As long as the token is generated from some secret known to the session or logged in user there should be no need to invalidate it when opening a new thread.

    Here’s one way to do this:

    1. When user logs in, create a secret that’s only stored in the session.
    2. In the form for the discussion thread create a hash made up from the session-secret, the forum thread in question and any other info you might find valuable in the situation.
    3. When user submits form, create a hash from the same information as above, and see if it matches what submitted in the form.

    Along with the normal measures for keeping the session secure (timeout, reset on login etc) this should keep your forms fairly safe without any inconvenience for the users.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

Many people suggest to develop web applications in open source technologies. And one of
I am a newbie in cryptographic system but i have seen many sources tell
Was overwriting a TextView class, and as I didn't find many sources, I was
We could not make the VB6.0 checkbox as a transparent one. Can you suggest
Effective Java , along with other sources suggest that we should consider using composition
There are many discussions on this topic already, but I am all about flogging
On many different sources you can read about time keeping issues in virtual machines.
I have a DataImporter class [takes data from many sources and processes it] that
I am studying macros and found many sources and questions regarding difference between macros
My .emacs is like a roadmap for me where I source many files. Their

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.