CSRF Tokens and SameSite Cookies
Primary Defense: CSRF Tokens
<input type="hidden" name="csrf-token" value="CIwNZNlR4XbisJF39I8yWnWX9wX4WFoz" />Additional Defense: SameSite Cookies
SameSite=Strict (Too Defensive)
SameSite=Strict (Too Defensive)SameSite=Lax (Use This)
SameSite=Lax (Use This)Reference
Last updated