Okay. So from a security point of view, do I need
SESSIONURL when passing an upload post from YUI to my PHP script?
There doesn't seem to be any official vBulletin/YUI guides yet. I've only found the stock reply indicating that connections should be called with this format.
Code:
YAHOO.util.Connect.asyncRequest('POST', scriptpath + '?do=ajax', {
success: this.handle_ajax_response,
failure: this.handle_ajax_error,
timeout: vB_Default_Timeout,
scope: this
}, SESSIONURL + 'securitytoken=' + SECURITYTOKEN + '&foo=' + foo);
This works for me using
SESSIONURL as part of the request, but as I mentioned above it isn't working with the YUI uploader example I posted.
Bottom line, do I need to find a way to incorporate
SESSIONURL (or
$sessionid as TigerC10 suggested) with YUI's uploader in order to fully take advantage of vBulletin's CSRF protection scheme?
Or will using
SECURITYTOKEN alone suffice?
Thanks,
James