Viewing profile — skeggse
skeggse
HN member- Joined
- Wed, Jun 01, 2016, 5:05 PM UTC
- HN karma
- 58
- Public activity
- 11 items
- HN profile
- View on Hacker News ↗
About skeggse
No profile information was provided.
Recent public activity
-
comment
Comment #36868900
https://docs.aws.amazon.com/whitepapers/latest/security-desi... seems like the relevant docs?
-
comment
Comment #36775558
DIY Edition. I restarted on my laptop instead of my phone and was able to get it through, though not before missing out on batch 2 :( I think there was something squirrely with my …
-
comment
Comment #36775128
When I click "Add pre-order to bag" it tells me "Please make a selection for each option." I have quadruple-checked, and I have definitely made a selection for each option. What gi…
- story
-
comment
Comment #14553716
You're right, support for cross-origin form POSTs isn't important for us. What is important, however, is same-origin requests, and Firefox doesn't send the Origin header with those…
-
comment
Comment #14550594
For our specific solution, we also rely on (partial) support for Referrer-Policy: https://caniuse.com/#feat=referrer-policy
-
comment
Comment #14550589
Well, it's a bug. It absolutely should send the origin header, but it doesn't ¯\_(ツ)_/¯
-
comment
Comment #14550573
I would like to note that not all frameworks are viable at-scale. We ran into that with Meteor, as it scaled extremely poorly. It didn't implement CSRF tokens, but also didn't use …
-
comment
Comment #14549442
I'm curious about your comment. We (attempted) to address cases where we needed to infer the Origin from the Referer due to incomplete browser support. What about using both makes …
- story
- story