- [Security] With CSRF tokens, is SameSite=Lax required? And storing CSRF tokens in cookies bad? https://cheatsheetseries.owasp.org/cheatsheets/Cross-Site_Request_Forgery_Prevention_Cheat_Sheet.html#double-submit-cookie 2 comments webdev
Linking pages
- GitHub - thedaviddias/Front-End-Checklist: 🗂 The perfect Front-End Checklist for modern websites and meticulous developers https://github.com/thedaviddias/front-end-checklist 106 comments
- The Ultimate Guide to handling JWTs on frontend clients (GraphQL) https://blog.hasura.io/best-practices-of-using-jwt-with-graphql 65 comments
- Nodejs Security - OWASP Cheat Sheet Series https://cheatsheetseries.owasp.org/cheatsheets/Nodejs_Security_Cheat_Sheet.html 45 comments
- How I Created My Own Authentication System https://blog.danidre.com/how-i-created-my-own-authentication-system 20 comments
- Learn Authentication The Hard Way: Part One • Andrew Best https://www.andrew-best.com/posts/learn-auth-the-hard-way-part-one/ 20 comments
- tiny-csrf - npm https://www.npmjs.com/package/tiny-csrf 17 comments
- How-to form submissions with Flask and AJAX | by Louis de Bruijn | JavaScript in Plain English https://medium.com/@leddebruijn/how-to-form-submissions-with-flask-and-ajax-dfde9891c620?amp%3Bsk=f23a8bfb7a7f503c442e057d8d381098&source=friends_link 16 comments
- Push API - Web APIs | MDN https://developer.mozilla.org/en-US/docs/Web/API/Push_API 12 comments
- Explaining the csurf vulnerability: CSRF attacks on all versions | Snyk https://snyk.io/blog/explaining-the-csurf-vulnerability-csrf-attacks-on-all-versions/ 11 comments
- GitHub - tinyhttp/malibu: 🏄 Framework-agnostic CSRF middleware for modern Node.js https://github.com/tinyhttp/malibu 10 comments
- Web Security 101: An Interactive Cross-Site Request Forgery (CSRF) Demo - victorzhou.com https://victorzhou.com/blog/csrf/ 7 comments
- csrf-csrf - npm https://www.npmjs.com/package/csrf-csrf 6 comments
- What’s the problem with the CSURF package? https://dev-academy.com/csurf-vulnerability/ 5 comments
- Cross-Site Request Forgery Prevention - OWASP Cheat Sheet Series https://www.owasp.org/index.php/CSRF_Prevention_Cheat_Sheet#Protecting_REST_Services:_Use_of_Custom_Request_Headers 4 comments
- iron-session - npm https://www.npmjs.com/package/iron-session#magic-links 3 comments
- Advanced Web Scraping With Python: Extract Data From Any Site https://jacobpadilla.com/articles/advanced-web-scraping-techniques 3 comments
- Clojure Web Security http://www.lispcast.com/clojure-web-security 1 comment
- GitHub - vvo/iron-session: 🛠 Secure, stateless, and cookie-based session library for JavaScript https://github.com/vvo/iron-session 1 comment
- Why are developers so vulnerable to drive-by attacks? | GitLab https://about.gitlab.com/blog/2021/09/07/why-are-developers-vulnerable-to-driveby-attacks/ 0 comments
- GitHub - isarisariver/webdev: A collection of helpful resources for web development. https://github.com/isarisariver/webdev 0 comments
Linked pages
- Can I use... Support tables for HTML5, CSS3, etc https://caniuse.com/#search=css%20grid 519 comments
- HTTP referer - Wikipedia https://en.wikipedia.org/wiki/HTTP_referer#Origin_of_the_term_referer 86 comments
- GitHub - axios/axios: Promise based HTTP client for the browser and node.js https://github.com/axios/axios 82 comments
- Chromium Blog: Developers: Get Ready for New SameSite=None; Secure Cookie Settings https://blog.chromium.org/2019/10/developers-get-ready-for-new.html 56 comments
- Window.postMessage() - Web APIs | MDN https://developer.mozilla.org/en-US/docs/Web/API/Window/postMessage 22 comments
- RFC 7231 - Hypertext Transfer Protocol (HTTP/1.1): Semantics and Content https://tools.ietf.org/html/rfc7231 15 comments
- Informationen zum Bug-Bounty-Programm von Meta https://www.facebook.com/whitehat/ 8 comments
- http://seclab.stanford.edu/websec/csrf/csrf.pdf 4 comments
- Set-Cookie - HTTP | MDN https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Set-Cookie 3 comments
- Forbidden header name - MDN Web Docs Glossary: Definitions of Web-related terms | MDN https://developer.mozilla.org/en-US/docs/Glossary/Forbidden_header_name 2 comments
- Egor Homakov: Playing With Referer & Origin http://homakov.blogspot.com/2012/04/playing-with-referer-origin-disquscom.html 0 comments
- Bei Facebook anmelden https://www.facebook.com/notes/facebook-bug-bounty/client-side-csrf/2056804174333798/ 0 comments
- Web Security https://infosec.mozilla.org/guidelines/web_security 0 comments
Would you like to stay up to date with Web Development? Checkout Web Development
Weekly.
Related searches:
Search whole site: site:cheatsheetseries.owasp.org
Search title: Cross-Site Request Forgery Prevention - OWASP Cheat Sheet Series
See how to search.