Unit content
Cross-site request forgery
A cross-site request forgery (CSRF) occurs when a browser sends an authenticated state-changing request that the user did not intend to authorize.
The attack is possible because browsers may attach credentials such as cookies automatically. A malicious page can sometimes cause the victim's browser to submit a request to another site while those credentials are present.
CSRF is different from stealing the session credential. The attacker may never learn the cookie; they abuse the browser's willingness to send it.
Common defenses include
- unpredictable CSRF tokens bound to the legitimate application context;
- checking trusted request-origin information where appropriate;
- suitable
SameSitecookie policies; - avoiding state changes through safe-navigation methods such as
GET.
CSRF protection is needed when ambient credentials are sent automatically. An API that requires an explicit bearer token in a header not automatically supplied cross-site has a different threat model.
The defense must distinguish a request deliberately initiated by the trusted application from one merely caused by an untrusted site.