Skip to content

Why is CSRF necessary? #1721

Answered by pilcrowonpaper
musjj asked this question in Help
Oct 24, 2024 · 1 comments · 1 reply
Discussion options

You must be logged in to vote
  1. There's still like 1-5% of users who don't use browser's that support SameSite=Lax
  2. Rare, but SameSite doesn't protect you from cross-origin request forgery

https://thecopenhagenbook.com/csrf#samesite-cookie-attribute

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@musjj
Comment options

Answer selected by musjj
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Help
Labels
None yet
2 participants