CSRF: Cross-Site Request Forgery

Difficulty: Intermediate

Question

What is CSRF and how do you stop it?

Answer

CSRF tricks a user's browser into performing actions on another site. Stop it using **SameSite=Lax/Strict** cookies and manual Anti-CSRF tokens for POST requests.

Concepts covered

CSRF, SameSite Cookie, Anti-CSRF Token, State-changing