0

Is there a way to only allow calls to come into a script through AJAX and not allow end users to access the page directly?

kapa
  • 77,694
  • 21
  • 158
  • 175
Jeffrey Hunter
  • 1,103
  • 2
  • 12
  • 19

1 Answers1

2

Short answer: Nope.

Long answer: AJAX is absolutely similar to "direct" access to the url. There is literally no difference between them. Actually there is: only one header that can be forged easily

zerkms
  • 249,484
  • 69
  • 436
  • 539