They allow the client to validate the token, or request that the valid time span for the token be extended or ended.
它们允许此客户机验证此令牌或者请求延长或终止此令牌的有效时间区间。
You can set the time-to-live to be longer than the validity of the original token request.
您可以将生存时间设置为比原先的令牌请求时间的有效期长。
Because the token is changed each time the form is drawn, a would-be attacker would have to get an instance of the sending form, strip out the token, and put it in their spoofing version of the form.
由于在每次调用表单时都会更改标记,因此想要成为攻击者就必须获得发送表单的实例,去掉标记,并把它放到假表单中。
应用推荐