Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 6826317
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 26, 20262026-05-26T22:07:57+00:00 2026-05-26T22:07:57+00:00

Now I think securing ajax calls, sometimes normal forms with a token is pretty

  • 0

Now I think securing ajax calls, sometimes normal forms with a token is pretty common. It works like this. 1) The user requests a page 2) a token is put into the html, and into the session 3) on submit these values are checked.

Now one major obstacle I am facing with this is caching. I do not have a lot of changing content, so I want to be able to cache for at least 24 hours. On the other hand, I do some ajax calls on the front-end, and good practice is to have them a little secured.

Now I was thinking of this, but I do not know if it will work. Maybe you can help.

  • user requests a site, and the cached site is given.
  • On the site, the first ajax call is made, which only asks a token
  • In the backend, a token is generated, stored in the session and sent to the front-end
  • The token is stored in a var in the frontend, and now sent with every call
  • On every call we check the session and the given token
  • If they match we do our DB stuff, if not we make a call to the FBI
  • The FBI takes over the case

Just kidding about the last part. But will this work, because you are not sending a piece of the actual website.

Maybe you can make it a little smarter by storing an identifier of the form the user requests.

Actually, I have no idea if this will work, I actually doubt it. Maybe someone can explain to me why this will not work.

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-26T22:07:57+00:00Added an answer on May 26, 2026 at 10:07 pm

    In order to prevent csrf with a token, each user must have a unique token that an attacker cannot guess. If you serve the same cached page to everyone, then the token isn’t a secret and an attacker can forge requests.

    That being said. You could have some JavaScript use an XHR to pull that users token from the user’s session data store and populate a form or in ajax calls.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

Dear all,Now i have this question in my java program,I think it should be
Well, i've walking around this for a couples of days now... I think is
I have a site that calls AJAX. It works at my office, where I
Updated: I now think this is an existing bug in Django reported as Ticket
I have been battling this issue for a few days now and think I
UPDATE2: I think I got it now: <?php /* * @name Lawler's algorithm PHP
I think I'm going a little crazy. Right now, I'm working with the following
I'm using guidelines right now, but I do not think there is any way
I have the following query, now the strange thing is if I run this
Ok now I think Im getting warmer, I have to pattern match whatever comes

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.