legacy-knowledge-base
公開されました Jun. 30, 2025

GETリクエストでp_authトークンが見つからない

written-by

Peter Schwarcz

How To articles are not official guidelines or officially supported documentation. They are community-contributed content and may not always reflect the latest updates to Liferay DXP. We welcome your feedback to improve How To articles!

While we make every effort to ensure this Knowledge Base is accurate, it may not always reflect the most recent updates or official guidelines.We appreciate your understanding and encourage you to reach out with any feedback or concerns.

legacy-article

learn-legacy-article-disclaimer-text

問題

  • CSRFトークンを有効にした後p_auth トークンが、期待どおりにURLに付加される。
  • しかし、手動でURLの末尾からこれを削除してエンターキーを押すと、 p_auth がリクエストから消えているにもかかわらず、ページにアクセスできることに気づいた。
  • これはCSRF保護が危ういことを意味するのか?

環境

  • Liferay DXP 7.4

解像度

  • いいえ、CSRF保護は損なわれていません。
  • p_auth トークンは、POST リクエストに対する CSRF 攻撃を防ぐためのものです。
  • GETもPOSTもCSRFの脆弱性を持つ可能性があるが、 RFC 9110 では、GETメソッドは検索以外のアクションを取るという意味を持つべきでないと述べている。 これらの方法は "安全 "だと考えるべきだ。 したがって、ウェブサイトが標準を守り、「安全でない」アクションをPOSTとしてのみ実装している場合、ここではPOSTリクエストのみが脆弱となる。
did-this-article-resolve-your-issue

legacy-knowledge-base