Part 2 of my series on multiplayer web games is live!
Using HttpOnly + CHIPS to stop XSS and tracking while keeping subdomains seamless. I *think* it describes a reasonable CSRF mitigation, thoughts?
🔗 www.rhelmer.org/blog/stellar...
#WebDev #InfoSec #WebSecurity #indiedev #gamedev