skip to content

CSRF

An attacker's page makes a logged-in browser fire a state-changing request at your site. Covers synchronizer tokens, SameSite and Origin checks. Interviewers use it to test ambient authority.

part ofWeb protocols & securityoverview, primer and where to startread it →
on this pageshow

questions

24

Your claim upload is rejected by the built-in CSRF token filter - why does answering 401 Unauthorized instead of 403 Forbidden mislead the client?

level: juniorimportance: must knowfreq 58%

basics

~20 s

A CSRF token mismatch is a provenance failure, not a credential one: the session cookie was valid, so 403 Forbidden fits. A 401 Unauthorized tells the client its credential is bad, so it discards a good session and forces a needless login.

open as a page

What does the Origin request header tell a server about an incoming POST, and what does it not?

level: juniorimportance: must knowfreq 58%

basics

~20 s

A conforming user agent, not page script, writes the Origin request header, so a value that is not yours means another document initiated the request. Its absence proves nothing, and a client that is not a browser can send any value.

open as a page

A booking form posts a hidden field holding an unpredictable value the server stored against the session - what does checking it prove?

level: juniorimportance: must knowfreq 74%

basics

~20 s

A matching value proves the request was composed by a page this site served: the value is unpredictable and its authoritative copy lives in server-side session state, so a document from elsewhere can neither read nor guess it.

open as a page

With no script at all, what requests can a hostile page emit at a clinic's cookie-authenticated booking endpoints?

level: middleimportance: must knowfreq 60%

basics

~20 s

Plain markup can emit a GET through any subresource or navigation, and a form POST whose body is one of three encodings: application/x-www-form-urlencoded, multipart/form-data or text/plain. It cannot add a request header field of its own.

open as a page

Why is the double-submit CSRF pattern a defence at all, given the server stores no token and only compares a cookie against the request?

level: middleimportance: must knowfreq 62%

basics

~20 s

The defence rests on what a document served by another site cannot do: read your cookie, or attach an author-defined header to a request it emits. Matching the two halves is evidence your own page authored the request.

open as a page

Why does comparing the Origin request header against an allowlist with a prefix test let an attacker's host pass?

level: middleimportance: must knowfreq 55%

basics

~10 s

An Origin value is a serialized scheme, host and optional port, and an attacker can register a host that starts with yours, such as booking.example.com.evil.test. Only byte-exact comparison against a fixed allowlist refuses it.

open as a page

A redelivery service's session cookie is SameSite=Lax; which cross-site forged requests still arrive carrying it?

level: middleimportance: must knowfreq 66%

basics

~20 s

Lax withholds the cookie from cross-site subresource loads and cross-site form POSTs, but attaches it to cross-site top-level navigations using a safe method. Any state change reachable by GET therefore stays forgeable, including a POST a redirect converts into one.

open as a page

Your server sets SameSite=Lax on a session cookie — what can the server verify about whether that attribute was honoured?

level: juniorimportance: should knowfreq 56%

basics

~20 s

Nothing. SameSite is enforced entirely by the client; the server only writes the attribute into Set-Cookie. An arriving request carries an ordinary Cookie header that looks the same whether the client honoured the attribute or never implemented it at all.

open as a page

A claim form sits open for an hour, its CSRF token is rejected, and resubmitting fails again - why?

level: middleimportance: should knowfreq 42%

basics

~20 s

The open page still carries the value it was rendered with, while the server now expects a different one. A fresh value issued in the rejection response never reaches that page, so resubmitting sends the same stale field and earns the same refusal.

open as a page

A booking form's server-issued anti-forgery token can ride in a hidden field or an author-set request header - what does each carriage assume?

level: middleimportance: should knowfreq 55%

basics

~20 s

A hidden field assumes the server rendered the form that carries it; an author-set header assumes your own code composed the request. The second is stronger, because a document from elsewhere can emit a request body but cannot set an author-defined header on it.

open as a page

A clinic's cancel-appointment endpoint acts on GET and the attacker never sees the response — why is the forgery still complete?

level: seniorimportance: should knowfreq 50%

basics

~20 s

The cancellation happens when the server handles the request, so reading the response adds nothing for the attacker. Safety in RFC 9110 is a contract about what a client may assume, not enforcement — an implementation is free to change state on GET, and this one has.

open as a page

How do you keep a double-submit CSRF value stateless while making a value planted by a sibling host fail the check?

level: seniorimportance: should knowfreq 42%

basics

~20 s

Bind the value to the session instead of only to itself: carry a random part plus a keyed message authentication code over the session identifier and that random part. The server recomputes it from the session it already has, so nothing is stored.

open as a page

Why can a CSRF token filter that runs before body parsing not validate a token carried in a multipart/form-data body?

level: seniorimportance: should knowfreq 46%

basics

~20 s

The value exists only once the body has been parsed. A check that runs ahead of the parser sees headers and an unread byte stream, so it has nothing to compare - and running it after the parser means the upload is already buffered or stored before provenance is known.

open as a page

A state-changing request arrives with neither an Origin nor a Referer request header — what should the server do, and why?

level: seniorimportance: should knowfreq 46%

basics

~20 s

Refuse it. With neither field the initiator is unverifiable, and allowing an unverifiable request is exactly the fall-through a forged request needs. Refusing also proves the check cannot be the whole defence, since legitimate traffic can land there.

open as a page

Your booking API receives a request whose Origin header value is the literal null — what produced that, and what should the server do?

level: seniorimportance: should knowfreq 36%

basics

~20 s

The literal null means the user agent would not disclose a usable initiator, and it identifies nothing, so it never belongs on an allowlist. Besides opaque contexts, a referrer policy on your own pages can produce it, so refuse the request and fix the cause.

open as a page

SameSite=Strict protects a redelivery session cookie; what does it stop from a compromised host under the same registrable domain?

level: seniorimportance: should knowfreq 44%

basics

~20 s

Nothing at all. Same-site is decided on the registrable domain, so any host beneath it is same-site with the service and its requests carry the session cookie in full, under Strict exactly as under Lax. SameSite is not a boundary between your own hosts.

open as a page

Per-request rotation of a CSRF token refuses a booking confirmed from a second tab or the back button - why, and what does rotation buy?

level: seniorimportance: should knowfreq 44%

basics

~20 s

Rendering a page under per-request rotation overwrites the one value stored against the session, so any page rendered earlier carries a superseded one. Rotation buys a shorter window in which a leaked value is still accepted, and nothing against a document that never held one.

open as a page

What is login CSRF against a clinic booking site, and why is signing a victim into the attacker's own account worth doing?

level: seniorimportance: nice to knowfreq 30%

basics

~20 s

Login CSRF forges a sign-in with the attacker's own credentials, so the victim's browser ends up holding the attacker's session. Everything the victim then does — pets added, a card saved, appointments booked — accrues to an account the attacker can log into and read.

open as a page

When a CSRF filter rejects a multipart claim upload, how does the redirect status it answers with affect the attached photographs?

level: seniorimportance: nice to knowfreq 29%

basics

~20 s

301 Moved Permanently and 302 Found permit a user agent to rewrite the POST as a GET, which discards the multipart body and the photographs with it. 307 Temporary Redirect and 308 Permanent Redirect preserve method and body - and therefore replay the value that was just refused.

open as a page

Why can a cookie sent with no SameSite attribute still ride a cross-site POST minutes after it was set?

level: seniorimportance: nice to knowfreq 28%

basics

~20 s

Because of a compatibility enforcement mode, not an attribute value. A user agent may treat a cookie that set no SameSite attribute as Lax while still allowing it on cross-site top-level requests with unsafe methods for a short period after creation; two minutes is cited as a reasonable limit.

open as a page

Why does a server mask or re-randomise a session-bound CSRF token in every response when the value is already unguessable?

level: seniorimportance: nice to knowfreq 24%

basics

~20 s

Because a secret that appears byte-for-byte in many responses is recoverable through a compression side channel: an attacker whose text is reflected into the same response and who can watch its compressed size learns the value piece by piece. Masking makes the transmitted bytes differ each time.

open as a page

A loyalty scheme is adding partner-operated brand hosts under its shared registrable domain — how should that change its stateless double-submit CSRF choice?

level: principalimportance: nice to knowfreq 28%

basics

~20 s

It makes explicit what the stateless choice always assumed: the defence's trust boundary is the whole registrable domain, not one host. Partners you do not operate are now inside it, so either shrink the boundary or stop depending on it.

open as a page