How automatically sent credentials enable CSRF

Coming soon
IntermediateDifficulty: Intermediate
DeveloperAudience: Developer
Security practitionerAudience: Security practitioner
Secure accessPurpose: Secure access

Wave 3 · Mechanisms · T02.05

Coming soon — this article is being prepared. Below are its question, intended outcome, and place in the story.

The question

Why can a browser send an authenticated request without the user’s intent?

What we will work through

Reproduce CSRF in a local teaching app and explain where credentials come from.

Before you begin

Previously covered: Cookie attributes: Domain, Path, Secure, and HttpOnly; SameSite and the boundaries of sites and origins.

Articles

Color theme

Language

Home