Fortinet white logo
Fortinet white logo

Administration Guide

JS event check for CSRF requests (7.6.1)

JS event check for CSRF requests (7.6.1)

Starting from version 7.6.1, FortiWeb can scan the CSRF requests using JavaScript embedded in the page.

To enable this function, turn on the JS Request Status in Web Protection > Advanced Protection > CSRF Protection.

Please note that the AJAX Check option in previous versions are now replaced by JS Request Status which provides more robust and comprehensive verification capabilities.

For more information, see Defeating cross-site request forgery (CSRF) attacks.

JS event check for CSRF requests (7.6.1)

JS event check for CSRF requests (7.6.1)

Starting from version 7.6.1, FortiWeb can scan the CSRF requests using JavaScript embedded in the page.

To enable this function, turn on the JS Request Status in Web Protection > Advanced Protection > CSRF Protection.

Please note that the AJAX Check option in previous versions are now replaced by JS Request Status which provides more robust and comprehensive verification capabilities.

For more information, see Defeating cross-site request forgery (CSRF) attacks.