当前位置:网站首页>【教程】chrome关闭跨域策略cors、samesite,跨域带上cookie
【教程】chrome关闭跨域策略cors、samesite,跨域带上cookie
2022-07-03 02:17:00 【云牧青】
谷歌浏览器允许跨域origin,disable samesite,方便本地开发调试,测试csrf跨站请求伪造漏洞
写稿时间:2022年6月30日
犹记得两年前,测试csrf漏洞时得心应手。现如今,csrf已成历史
chrome,Firefox更新迭代到现在,已将跨域请求打到苟延残喘
苦了本地调试的开发人员,前端一个端口,后端一个端口,就跨域无法带cookie了
网上广为流传的开启跨域的方法,以以下命令启动chrome:
"C:\Program Files\Google\Chrome\Application\chrome.exe" --disable-web-security --user-data-dir="D:\ChromeDevUserData"
这会启动一个和你原本chrome互不干扰的浏览器,但目前实测最新版浏览器,依旧不能复现csrf,但是用以下增强版,似乎是能解决本地调试前后端时的跨域问题的
"C:\Program Files\Google\Chrome\Application\chrome.exe" --disable-site-isolation-trials --disable-web-security --disable-features=SameSiteByDefaultCookies,CookiesWithoutSameSiteMustBeSecure --user-data-dir="D:\ChromeDevUserData"
依旧不能复现csrf,想复现,只能使用旧版chrome
旧版chrome可以在这里直接下载:https://www.chromedownloads.net/chrome64win-stable/
如果不想用百度云盘,而且想在官网下载的话,可以这样操作
- 根据chrome版本号,找到内部的版本号
https://omahaproxy.appspot.com/
- 根据内部版本号,去下载离线包
https://commondatastorage.googleapis.com/chromium-browser-snapshots/index.html
亲测可用的版本:722274,19年12月的版本
选win64 zip使用上述增强参数启动即可
边栏推荐
- Explore the conversion between PX pixels and Pt pounds, mm and MM
- MySQL学习03
- 5. File operation
- 单词单词单词
- A 30-year-old software tester, who has been unemployed for 4 months, is confused and doesn't know what to do?
- 浏览器是如何对页面进行渲染的呢?
- Kotlin middle process understanding and Practice (I)
- 我的创作纪念日
- The sandbox explains its vision for the meta universe platform
- Where is the future of test engineers? Confused to see
猜你喜欢

Trial setup and use of idea GoLand development tool

Redis: simple use of redis
![[camera topic] complete analysis of camera dtsi](/img/cb/d42589fcf0610600c9dc8c7992d4d7.png)
[camera topic] complete analysis of camera dtsi

Return a tree structure data

Query product cases - page rendering data

通达OA 首页门户工作台

y54.第三章 Kubernetes从入门到精通 -- ingress(二七)

全链路数字化转型下,零售企业如何打开第二增长曲线

Job object of collaboration in kotlin

微服务组件Sentinel (Hystrix)详细分析
随机推荐
Explore the conversion between PX pixels and Pt pounds, mm and MM
awk从入门到入土(2)认识awk内置变量和变量的使用
Asian Games countdown! AI target detection helps host the Asian Games!
[shutter] bottom navigation bar implementation (bottomnavigationbar bottom navigation bar | bottomnavigationbaritem navigation bar entry | pageview)
awk从入门到入土(0)awk概述
微信小程序開發工具 POST net::ERR_PROXY_CONNECTION_FAILED 代理問題
Startup mode and scope builder of collaboration in kotlin
CFdiv2-Fixed Point Guessing-(區間答案二分)
PyTorch 卷积网络正则化 DropBlock
Unrecognized SSL message, plaintext connection?
[Yu Yue education] reference materials of chemical experiment safety knowledge of University of science and technology of China
Coroutinecontext in kotlin
502 (bad gateway) causes and Solutions
String replace space
[shutter] pull the navigation bar sideways (drawer component | pageview component)
Deep learning notes (constantly updating...)
Anna: Beibei, can you draw?
Distributed transaction solution
单词单词单词
Awk from getting started to getting into the ground (3) the built-in functions printf and print of awk realize formatted printing