Skip to main content

You are not logged in. Your edit will be placed in a queue until it is peer reviewed.

We welcome edits that make the post easier to understand and more valuable for readers. Because community members review edits, please try to make the post substantially better than how you found it, for example, by fixing grammar or adding additional resources and hyperlinks.

5
  • even without SOP, a response (maybe containing a token) from a server would go to requesting page, not visible to all tabs right ? Commented Feb 8, 2015 at 23:02
  • Same tab, yes. As for it not being visible... that depends on the browser architecture. Whether its Javascript engine allows access to a windows array. Chances are that it would. Commented Feb 9, 2015 at 6:51
  • @LSerni If chances are it would, then CSRF tokens are of no use right?? As we can get CSRF token that way. Commented May 28, 2018 at 12:48
  • @SurajJain unless you had SOP. That's why I said that SOP is what makes CSRF work. Commented May 28, 2018 at 13:02
  • Oh, Yeah right. Also security.stackexchange.com/a/72569/166709, this answer first attack example isn't it wrong 'But because of the SOP, the browser prevents this request from being made.' Because SOP never stops the request to be made only the responses we cannot read. Commented May 28, 2018 at 13:06