CSRF & SameSite Cookies
How cross-site request forgery actually works in the browser, why the SameSite cookie attribute changed everything, the four classic defence patterns (synchronizer token, double-submit, signed double-submit, custom header), and the six common ways developers mis-implement them.
Members Only Content
This article is exclusively available to registered members of LazyHackers. Login or subscribe to read.