This page is not created by, affiliated with, or supported by Slack Technologies, Inc.
2022-08-05
Channels
- # announcements (1)
- # babashka (16)
- # beginners (36)
- # biff (1)
- # calva (2)
- # cider (4)
- # cljdoc (1)
- # clojure (118)
- # clojure-austin (2)
- # clojure-czech (2)
- # clojure-europe (19)
- # clojure-norway (3)
- # clojure-spec (8)
- # clojure-uk (3)
- # clojurescript (11)
- # conjure (1)
- # cursive (3)
- # datalevin (5)
- # datomic (7)
- # emacs (16)
- # events (1)
- # figwheel-main (3)
- # fulcro (5)
- # hyperfiddle (17)
- # jobs (2)
- # lsp (19)
- # malli (5)
- # nbb (10)
- # off-topic (5)
- # polylith (5)
- # re-frame (3)
- # reagent (11)
- # remote-jobs (2)
- # shadow-cljs (1)
- # spacemacs (7)
- # web-security (4)
Sente requires a csrf token to create the client connection. Which i assume gets sent back to the server to get verified. However, the examples confuse me because i expect the csrf token to be per user session or per request, and in the example there pulling it from the index.html, which isn't really bound to a specific session or request. And In many setups you have a CDN cache an index.html and send it to multilpe users, usually they prompt the user to login, and then the SPA is loaded.
So maybe what's making this hard is that the login depends on the websocket connection.
actually i might be falsely assuming a user session "starts" after they login.
yea, i guess in this case, were just worried about cross site, not cross user leaks.