Stick a uuid in a hidden field and check that you get the same one back.
cgi.http_referer can't be trusted as it can be easily spoofed.

Andrew Grosset wrote:

> Is there an alternative to cgi.http_referer when checking that a form
> submission originated from the form page?
>
[Todays Threads] [This Message] [Subscription] [Fast Unsubscribe] [User Settings]

Reply via email to