#41 FTX-41: CSRF + Action Web session + OTP in Redis
Description
EditSigned HttpOnly session cookie on review GET + double-submit CSRF on all Action Web POSTs (UB-AW-6, UB-TOK-5, UN-SEC-2); OTP moves to Redis (hashed code, TTL, atomic attempts max 5, single-use); step-up decided by policy snapshot not client form field (current require_otp param is a bypass). Phase 1.
Comments
Loading comments...
Context
Loading context...
Audit History
View AllLoading audit history...