CSRF¶
- Cookies Security
- HttpOnly
- Secure
- Domain, Path, SameSite
- HTML Element
- GET:
<img>,<iframe>,<form> - POST:
<form>
- GET:
- JavaScript
- GET/POST:
fetch,XMLHttpRequest
- GET/POST:
- Limitation
- Mitigation
- Same-origin policy (SOP)
- CSRF token
<img>, <iframe>, <form><form>fetch, XMLHttpRequest