Implementing CSRF protection with a synchronizer token

Coming soon
IntermediateDifficulty: Intermediate
DeveloperAudience: Developer
Security practitionerAudience: Security practitioner
Secure accessPurpose: Secure access

Wave 4 · Implementations and alternatives · T02.06

Coming soon — this article is being prepared. Below are its question, intended outcome, and place in the story.

The question

How can you reject requests without a session-bound CSRF token?

What we will work through

Reject requests without a session-bound CSRF token.

Before you begin

Previously covered: How automatically sent credentials enable CSRF.

Articles

Color theme

Language

Home