🎫
Security

CSRF tokens: form security

22.02.2025
← All articles

CSRF — performing action on site as a logged-in user.

Mechanism

Logged into bank.uz → visit hacker.com → form silently submits POST to bank.uz.

CSRF token

Hidden input with random string. Server verifies.

SameSite cookies

Set-Cookie: SameSite=Strict.

Custom header

X-CSRF-Token for AJAX.

Related articles

🔐 Password managers — choosing between Bitwarden, 1Password, LastPass and KeePass 🍯 Honeypot — hidden form field that catches bots and stops spam 📄 /.well-known/security.txt — security contact standard 📋 GDPR Compliance — obligations for protecting European citizens' data
🌐 Language
🇺🇿 O'zbek 🇺🇿 Ўзбек 🇷🇺 Русский 🇬🇧 English ✓