Forum Discussion
Jesus_Rodrigue2
Nimbostratus
Oct 01, 2014ASM CSRF Expiration Time token
Hello
I have recently implemented CSRF protection on few web based applications, so far so good but now I would like to enable expiration-time on the token so that it will be renewed every x sec...
boneyard
MVP
Nov 17, 2014i don't believe it works quite like that. it is the time the cookie is valid for after the page has been send, else you get an event that it isn't valid and you have to submit the request again ( i believe that means reloading the page ).
so i wouldn't set it too low because your users will get blocked requests.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects