Skip to content
EduVerse

CSRF

Explained

Concept

Also known as: Cross-Site Request Forgery

An attack where a malicious site sends requests on behalf of a logged-in user without their knowledge.

CSRF, explained

Written by EduVerse

What it is

CSRF (Cross-Site Request Forgery) is an attack where another website makes your browser send a request to a site you’re logged in to. Because browsers attach cookies automatically, the target site sees an ordinary request with a valid session and can’t tell that you never meant to send it.

Why teams use it

Any action that changes something, like updating an email address or transferring money, could be triggered this way. The usual defenses are a CSRF token, a secret value the server puts in each form and checks on submit, and the SameSite cookie setting, which stops browsers from sending cookies with most cross-site requests.

An example from work

You add a POST endpoint to a Spring Boot app that uses Spring Security, call it from Postman, and get 403 Forbidden while GET requests work fine. Spring Security’s CSRF protection is rejecting the request because it carries no CSRF token. Send the token the way the framework expects, rather than switching the protection off without understanding why.

Our own explanation, not a quote from the book.

In the book

Sentences from The Software Realm, Decoded that mention CSRF, exactly as printed.

    2 more passages about CSRF in the full book

    Read every conversation where CSRF comes up, with the interactive slides and demos.

    See the book

    Where it fits

    Web security, protecting forms and state-changing actions

    Coverage in the book

    Explained

    Explained and compared with alternatives, so you know where and why it’s used.

    Appears in