Forum Discussion
sandy16
Altostratus
May 05, 2015CSRF protection if HTTP response is compressed
Hi, we plan to enable CSRF protection on the F5. As per the below solution, under the requirements it states that the response should NOT be compressed. - https://support.f5.com/kb/en-us/solutions/public/11000/900/sol11930.html
Is this referencing the response from the server or from the F5?
thnx
1 Reply
- BinaryCanary_19Historic F5 Account
It's server-side response.
The solution says that: ASM modifies the response in order to insert the CSRF javascript, and it only does it for responses that contain tag
, and which are uncompressed.html
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects