Learning path

Full curriculum

Full curriculum

Arrows go from each prerequisite to the units that depend on it. Hover or focus a unit to highlight its path.

Unit content

Cross-site request forgery

A cross-site request forgery (CSRF) occurs when a browser sends an authenticated state-changing request that the user did not intend to authorize.

The attack is possible because browsers may attach credentials such as cookies automatically. A malicious page can sometimes cause the victim's browser to submit a request to another site while those credentials are present.

CSRF is different from stealing the session credential. The attacker may never learn the cookie; they abuse the browser's willingness to send it.

Common defenses include

  • unpredictable CSRF tokens bound to the legitimate application context;
  • checking trusted request-origin information where appropriate;
  • suitable SameSite cookie policies;
  • avoiding state changes through safe-navigation methods such as GET.

CSRF protection is needed when ambient credentials are sent automatically. An API that requires an explicit bearer token in a header not automatically supplied cross-site has a different threat model.

The defense must distinguish a request deliberately initiated by the trusted application from one merely caused by an untrusted site.