Cybersecurity › Web Application Security
Prevent CSRF
22 ControlsPreventing Cross-Site Request Forgery (CSRF)
CSRF forces a logged-on victim's browser to send a forged HTTP request, including session cookies.
- Implement anti-CSRF state tokens (Synchronizer Token Pattern)
- Use
SameSite=LaxorSameSite=Strictflag on session cookies - Require re-authentication for highly sensitive actions