Coming soon — this article is being prepared. Below are its question, intended outcome, and place in the story.
The question
Why can a browser send an authenticated request without the user’s intent?
What we will work through
Reproduce CSRF in a local teaching app and explain where credentials come from.
Before you begin
Previously covered: Cookie attributes: Domain, Path, Secure, and HttpOnly; SameSite and the boundaries of sites and origins.