Web Hacking Members Only

CSRF & SameSite Cookies

How cross-site request forgery actually works in the browser, why the SameSite cookie attribute changed everything, the four classic defence patterns (synchronizer token, double-submit, signed double-submit, custom header), and the six common ways developers mis-implement them.

Related Articles