CSRF Protection Techniques
The cluster focuses on discussions about Cross-Site Request Forgery (CSRF) attacks, including the use of CSRF tokens, SameSite cookies, and comparisons to CORS and other mitigations.
Activity Over Time
Top Contributors
Keywords
Sample Comments
That's just standard CSRF stuff isn't it
Will this means we no longer need the CSRF token technique to protect against cross site requests ?
you can use same-site cookie attribute to prevent csrf attacks these days.
CSRF doesn't save you here... I can send up a CSRF token using curl just as easily...
you might not need more advanced csrf protection than a cookie samesite policy.
If you don't even have a CSRF you actually probably have an issue that you are not aware of.
What you are describing isn't even CSRF
CSRF won't protect against traffic sniffing; only third parties constructing URLs.
It kills Cross-Site Request Forgery (CSRF): https://news.ycombinator.com/item?id=19854328
CSRF is about preventing other websites from making requests to your page using the credentials (including cookies) stored in the browser. Cookies can't prevent CSRF, in fact they are the problem to be solved.