FerryDocs
ArchitectureSecurity model

Changes come from the dashboard only

The server refuses a change that has the session cookie but comes from another origin.

Edit on GitHub
Dashboardsame originAnother pageother originServeraccepted

The dashboard sends a change with the session cookie. The server accepts it.

1 / 3

A POST, PUT, PATCH or DELETE request with the must come from the of the dashboard. This rule protects you when you open a bad page while your browser has a session.

How the server tests the request

  1. The server reads the Sec-Fetch-Site .
  2. If the browser did not send it, the server compares the Origin header with the host.

If the test fails, the server sends this answer:

AnswerMessage
403 cross_site_requestthis request doesn't come from the dashboard

You have nothing to set. The protection is always on.

On this page