Forum Discussion
ASM CSRF protection- how this works and effectiveness
Hi, I am trying to figure out how effective CSRF protection in ASM? How ASM effectively blocks the CSRF? I know this is by using anti-CSRF token but could you enlighten me with some more details?
Another question, my client has already implemented anti-csrf token in the application level now he is asking what advantage ASM provides? yes, there could be coding errors but apart from that what else? I read that ASM injects some scripts which may cause some issue. please share your expertise..cheers
1 Reply
- nathe
Cirrocumulus
At a high level it injects a Javascript token into the response. See Overview of the ASM CSRF protection feature for more details.
For this reason it may not always be compatible with you web application and so i would strongly suggest a DEV or UAT environment first. If the web app itself can be configured to use CSRF protection then that's probably the best place for it as it should integrate better. That being said if a web app doesn't allow this feature then using ASM is fairly simple and straightforward to setup.
Hope this helps,
N
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com