Тёмный
No video :(

Better WordPress Security with WordPress Nonces | WordPress PHP Security 

WPCasts
Подписаться 30 тыс.
Просмотров 9 тыс.
50% 1

Опубликовано:

 

22 авг 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 29   
@WPCasts
@WPCasts 4 года назад
Let's chat on Twitter! twitter.com/AlexanderBYoung
@patrickcameron2950
@patrickcameron2950 4 года назад
I'm a lot closer to wrapping my head around nonces than I was before - thank you! Looking forward to digging through your other videos.
@jlcdrivewayramps7343
@jlcdrivewayramps7343 Год назад
simple. clear. I cant stand tutorials which are too complex. they confuse more than help. keep it simple and you did. thank you.
@RyanDewhurst
@RyanDewhurst 4 года назад
Hey! Ryan here from WPScan. Great video. Just something to note that wasn't mentioned is that Chrome and other browsers will soon be enabling "SameSite=Lax" cookies by default, which will prevent most CSRF attacks in modern web browsers, when they implement it by default. Nonces should absolutely still be used of course, but the risk of a CSRF attack should also be reduced when web browsers implement SameSite by default.
@LevyCarneiro
@LevyCarneiro 4 года назад
Great format with you facing diagonally. Best format I've seen for screencast videos.
@leebuckle8288
@leebuckle8288 4 года назад
People in the UK reading the title like -.-
@manavbudhia
@manavbudhia 4 года назад
Great to see your video after long time..
@wassy83
@wassy83 4 года назад
Thank you so much!
@MoserDamasceno
@MoserDamasceno 4 года назад
Thank you!
@rauljauregi6615
@rauljauregi6615 4 года назад
nice! Thank you very much
@TheMarouuu
@TheMarouuu 4 года назад
Great stuff!
@Pharoxx105
@Pharoxx105 4 года назад
Could you explain how to use a nonce with cached form pages? I want to serve the form page from a static cache
@patrickcameron2950
@patrickcameron2950 4 года назад
Perhaps best to just exclude that page from caching?
@alex_ishchenko
@alex_ishchenko 4 года назад
Thanks!
@vladtircomnicu1630
@vladtircomnicu1630 3 года назад
Super useful
@gorangagrawal
@gorangagrawal 2 года назад
How to get NOnce for Headless WordPress? Custom endpoint i.e with REST API? And if yes then should we secure the Nonce endpoint by checking like current_user_can() or should just let it be without any checks?
@RhyandMarketingGroup
@RhyandMarketingGroup 4 года назад
Always love how you dig deeper into WP more than the average channel! Check out the function check_ajax_referer() (developer.wordpress.org/reference/functions/check_ajax_referer/). It pretty much does what you built, but with a simple function call. It's super handy.
@muhammadfarooqi
@muhammadfarooqi 3 года назад
it's not useful.... it is very useful....:) thankx
@WPCasts
@WPCasts 3 года назад
Glad to hear that!
@amitbiswas1885
@amitbiswas1885 4 года назад
What happens if user open this form as not logged in state and then login in another tab, return to first tab and submit the form? Nonce error happens. Why? how to deal with that situation?
@msvmanikantasrivishnu7788
@msvmanikantasrivishnu7788 4 года назад
1st like :-)
@WPCasts
@WPCasts 4 года назад
🎉 woot!
@afflictionmarketing5303
@afflictionmarketing5303 4 года назад
I don't understand it. Because the nonce filed is a hidden field. Evey when bot submit the request still isset return true and query get executed. ????
@user-ck7rb1hg8o
@user-ck7rb1hg8o 4 года назад
Note that the nonces are unique to the current user's session, so if a user logs in or out asynchronously any nonces on the page will no longer be valid. codex.wordpress.org/WordPress_Nonces
@Draanor
@Draanor 4 года назад
Nonces are to stop replay attacks, they are to help ensuring that a request was made from a valid source and that the request is only run only once and that the primed request can expire if the user fails to submit. Nonces are basically useless on forms that don't require user authentication.
@ReLLaKaT316
@ReLLaKaT316 3 года назад
Noooonce
@user-ck7rb1hg8o
@user-ck7rb1hg8o 4 года назад
Hello, what are you using for bundling JS?
@WPCasts
@WPCasts 4 года назад
I actually wasn't bundling it. I was just using the browser-supported ES6 :)
Далее
Create Custom User Capabilities in WordPress
12:50
Просмотров 11 тыс.
Italians vs @BayashiTV_  SO CLOSE
00:30
Просмотров 4,7 млн
Watch me hack a Wordpress website..
28:52
Просмотров 193 тыс.
How To Create Dynamic Routes In WordPress
16:15
Просмотров 17 тыс.
I forced EVERYONE to use Linux
22:59
Просмотров 415 тыс.
No, Flexbox isn't "good enough"
9:18
Просмотров 38 тыс.
Custom Queries In WordPress
14:50
Просмотров 20 тыс.