CSRF
ExplainedConcept
Also known as: Cross-Site Request Forgery
An attack where a malicious site sends requests on behalf of a logged-in user without their knowledge.
CSRF, explained
Written by EduVerseWhat it is
CSRF (Cross-Site Request Forgery) is an attack where another website makes your browser send a request to a site you’re logged in to. Because browsers attach cookies automatically, the target site sees an ordinary request with a valid session and can’t tell that you never meant to send it.
Why teams use it
Any action that changes something, like updating an email address or transferring money, could be triggered this way. The usual defenses are a CSRF token, a secret value the server puts in each form and checks on submit, and the SameSite cookie setting, which stops browsers from sending cookies with most cross-site requests.
An example from work
You add a POST endpoint to a Spring Boot app that uses Spring Security, call it from Postman, and get 403 Forbidden while GET requests work fine. Spring Security’s CSRF protection is rejecting the request because it carries no CSRF token. Send the token the way the framework expects, rather than switching the protection off without understanding why.
Our own explanation, not a quote from the book.
In the book
Sentences from The Software Realm, Decoded that mention CSRF, exactly as printed.
2 more passages about CSRF in the full book
Read every conversation where CSRF comes up, with the interactive slides and demos.
Where it fits
Web security, protecting forms and state-changing actions
Coverage in the book
Explained and compared with alternatives, so you know where and why it’s used.