<https://github.com/lenmorld/security_topics/tree/master/base_server>
<https://github.com/lenmorld/security_topics/tree/master/base_server_manual_session>
Cross-site Request Forgery
Attacker can hijack a logged-in user’s session,
to forge state-changing requests to server under user’s guise
mitigations:
- don’t use GET request for state-changing requests
- CSRF synchronizer token - CSRF token linked to user session; sent to client part of a response payload*; client sends this back to server as a request param**
- Double submit cookie - CSRF token not linked to session; sent to client as a Cookie separate from session; client sends this back to server in cookie and request param**
- Custom header - only JS in same domain can add a custom CSRF header. Value is not important; good for API or stateless
- SameSite cookie attribute (additional protection)
- Checking origin and target headers to block cross-origin requests
* response payload - HTML or JSON response
** request param - hidden form input or JSON payload on AJAX/fetch
Intro