Steven
in addition to the above suggestions (which for life I canโt understand why they work CS). In any case, you can also check the origin of the request inside the controller:
var origReq = HttpContext.Request.UrlReferrer;
or, view the headers and determine your action based on the content:
var headers = HttpContext.Request.Headers;
[edit] - of course, "headers" can be faked (depending on how x'post was determined by someone on your site), so you could probably use them for informational purposes only - this is not 100% confidence...
you can decide whether this โmessageโ is allowed or not, depending on whether it originated from your domain (or an approved domain) or not.
Jim
source share