---
title: "How automatically sent credentials enable CSRF"
description: "Why can a browser send an authenticated request without the user's intent?"
status: "coming-soon"
language: "en"
canonical: "https://bulnik.dev/en/articles/topics/T02.05/"
topicId: "T02.05"
---

> Coming soon — this article is being prepared. Below are its question, intended outcome, and place in the story.

## The question

Why can a browser send an authenticated request without the user's intent?

## What we will work through

Reproduce CSRF in a local teaching app and explain where credentials come from.

## Before you begin

Previously covered: Cookie attributes: Domain, Path, Secure, and HttpOnly; SameSite and the boundaries of sites and origins.

- [Cookie attributes: Domain, Path, Secure, and HttpOnly](/en/articles/topics/T02.03/)
- [SameSite and the boundaries of sites and origins](/en/articles/topics/T02.04/)
