You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

同一设备双标签页打开同页面时CSRF Token的取值及验证疑问

Why Your First Tab's Form Still Submits Successfully Despite New CSRF Tokens in Other Tabs

Great question! Let me break down this behavior based on how real-world CSRF protection implementations work—your initial assumption about token overwriting is a common misconception, so let's clear it up:

  • Most CSRF tokens are session-bound, not per-request
    The vast majority of frameworks (like Django, Spring Boot, Rails) generate a single CSRF token tied to your user session. This token stays the same for the entire duration of your session, no matter how many tabs or forms you open. When you load the form in a new tab, the server injects the same token into the form and checks if your cookie already has it—if it does, it won't overwrite it. So both tabs have matching cookie and form tokens, which is why the first tab's submission still works.

  • Some systems allow multiple valid tokens (instead of overwriting)
    Even in implementations that generate new tokens per form load, servers rarely invalidate old tokens immediately. Instead, they store a list of valid tokens linked to your session. When you submit a form, the server checks if the submitted token exists in this list—not just if it's the latest one. So opening a new tab creates token2, but token1 is still marked as valid, letting your first tab's submission pass.

  • Cookie updates are often conditional
    Servers don't always overwrite the CSRF token cookie when you load a new form. Many implementations only set the cookie if it doesn't already exist, or only update it when your session is refreshed (like after logging in again). This means your original token remains in the cookie even after opening new tabs, keeping the first tab's form and cookie in sync.

The key takeaway here is that CSRF protection is designed to be user-friendly. If every new tab invalidated old tokens, users would run into frustrating errors when filling out forms in multiple tabs—framework developers avoid this by using session-bound tokens or allowing multiple valid tokens.

内容的提问来源于stack exchange,提问作者samshers

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.09 17:17:43