CSRF
cross site request forgery
Example¶
blog (or embedded element): click a link to
bank.com/transfer?to=124&amount=1000
already logged in to bank.com => it'll work
Avoiding a CSRF attack¶
- Same site cookie- (Default is lax??)
 
- CSRF token- hidden input in form
- Nonce
 
- HTTP only cookies
- Backend can check origin referrer header
- Captcha
  
    
      Last update:
      2023-04-24