<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	
	>
<channel>
	<title>Comments on: Secure Forms with Zend Framework</title>
	<atom:link href="/2010/04/09/secure-forms-with-zend-framework/feed/" rel="self" type="application/rss+xml" />
	<link>/2010/04/09/secure-forms-with-zend-framework/</link>
	<description>on web development</description>
	<lastBuildDate>Fri, 26 Oct 2018 21:40:18 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>https://wordpress.org/?v=5.0.3</generator>
	<item>
		<title>By: Alex</title>
		<link>/2010/04/09/secure-forms-with-zend-framework/comment-page-1/#comment-15604</link>
		<dc:creator><![CDATA[Alex]]></dc:creator>
		<pubDate>Sun, 22 Apr 2012 20:40:18 +0000</pubDate>
		<guid isPermaLink="false">/?p=1421#comment-15604</guid>
		<description><![CDATA[Hi,

nice article, but i have a question:

You wrote: &quot;For more to test this you may try to make the same form somewhere else on the web and to point the action to http://www.stoimen.com/projects/php.secure.forms/&quot;

I copied the sourccode from the demo and pasted it in a webpage on my local server. (with the action to your webpage). First time after submitting the form from the local server i could see the value on your page. (because the token is right). By submitting the form more then 1 time, i see dont&#039;hack on your page (because the token changed). 
Is this the right behavior? I thougt first time after submitting i see &quot;don&#039;t hack&quot;, because the form was not submitted from your page.]]></description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>nice article, but i have a question:</p>
<p>You wrote: &#8220;For more to test this you may try to make the same form somewhere else on the web and to point the action to <a href="http://www.stoimen.com/projects/php.secure.forms/" rel="nofollow">http://www.stoimen.com/projects/php.secure.forms/</a>&#8221;</p>
<p>I copied the sourccode from the demo and pasted it in a webpage on my local server. (with the action to your webpage). First time after submitting the form from the local server i could see the value on your page. (because the token is right). By submitting the form more then 1 time, i see dont&#8217;hack on your page (because the token changed).<br />
Is this the right behavior? I thougt first time after submitting i see &#8220;don&#8217;t hack&#8221;, because the form was not submitted from your page.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
