当前位置:网站首页>【教程】chrome关闭跨域策略cors、samesite,跨域带上cookie
【教程】chrome关闭跨域策略cors、samesite,跨域带上cookie
2022-07-03 02:17:00 【云牧青】
谷歌浏览器允许跨域origin,disable samesite,方便本地开发调试,测试csrf跨站请求伪造漏洞
写稿时间:2022年6月30日
犹记得两年前,测试csrf漏洞时得心应手。现如今,csrf已成历史
chrome,Firefox更新迭代到现在,已将跨域请求打到苟延残喘
苦了本地调试的开发人员,前端一个端口,后端一个端口,就跨域无法带cookie了
网上广为流传的开启跨域的方法,以以下命令启动chrome:
"C:\Program Files\Google\Chrome\Application\chrome.exe" --disable-web-security --user-data-dir="D:\ChromeDevUserData"
这会启动一个和你原本chrome互不干扰的浏览器,但目前实测最新版浏览器,依旧不能复现csrf,但是用以下增强版,似乎是能解决本地调试前后端时的跨域问题的
"C:\Program Files\Google\Chrome\Application\chrome.exe" --disable-site-isolation-trials --disable-web-security --disable-features=SameSiteByDefaultCookies,CookiesWithoutSameSiteMustBeSecure --user-data-dir="D:\ChromeDevUserData"
依旧不能复现csrf,想复现,只能使用旧版chrome
旧版chrome可以在这里直接下载:https://www.chromedownloads.net/chrome64win-stable/
如果不想用百度云盘,而且想在官网下载的话,可以这样操作
- 根据chrome版本号,找到内部的版本号
https://omahaproxy.appspot.com/
- 根据内部版本号,去下载离线包
https://commondatastorage.googleapis.com/chromium-browser-snapshots/index.html
亲测可用的版本:722274,19年12月的版本
选win64 zip使用上述增强参数启动即可
边栏推荐
- awk从入门到入土(2)认识awk内置变量和变量的使用
- What are the differences between software testers with a monthly salary of 7K and 25K? Leaders look up to you when they master it
- 4. 类和对象
- 缺少库while loading shared libraries: libisl.so.15: cannot open shared object file: No such file
- 5. File operation
- 微信小程序开发工具 POST net::ERR_PROXY_CONNECTION_FAILED 代理问题
- Awk from entry to burial (1) awk first meeting
- [Flutter] dart: class; abstract class; factory; Class, abstract class, factory constructor
- es6 filter() 数组过滤方法总结
- Prohibited package name
猜你喜欢

A 30-year-old software tester, who has been unemployed for 4 months, is confused and doesn't know what to do?

stm32F407-------ADC

y54.第三章 Kubernetes从入门到精通 -- ingress(二七)

Use go language to realize try{}catch{}finally

8 free, HD, copyright free video material download websites are recommended

Awk from introduction to earth (0) overview of awk
![[camera topic] complete analysis of camera dtsi](/img/cb/d42589fcf0610600c9dc8c7992d4d7.png)
[camera topic] complete analysis of camera dtsi

Coroutinecontext in kotlin

Detailed introduction to the usage of Nacos configuration center

stm32F407-------DMA
随机推荐
[Flutter] dart: class; abstract class; factory; Class, abstract class, factory constructor
Answers to ten questions about automated testing software testers must see
[shutter] top navigation bar implementation (scaffold | defaulttabcontroller | tabbar | tab | tabbarview)
创建+注册 子应用_定义路由,全局路由与子路由
Reprint some Qt development experience written by great Xia 6.5
Redis:Redis的简单使用
COM和CN
Pytorch convolution network regularization dropblock
stm32F407-------DMA
线程安全的单例模式
Detailed analysis of micro service component sentinel (hystrix)
Recommendation letter of "listing situation" -- courage is the most valuable
Awk from getting started to getting into the ground (3) the built-in functions printf and print of awk realize formatted printing
Producer consumer model based on thread pool (including blocking queue)
Machine learning notes (constantly updating...)
返回一个树形结构数据
Trial setup and use of idea GoLand development tool
Return a tree structure data
Solution for processing overtime orders (Overtime unpaid)
Query product cases - page rendering data