4 ms·
Well, for a long time there was no SameSite browser support for cookies, CSRF was a vulnerability (excluding STP and other techniques to avoid it).
by snak 7y ago
Well, for a long time there was no SameSite browser support for cookies, CSRF was a vulnerability (excluding STP and other techniques to avoid it).
- tmikaeld 7y agoYou're right, SameSite became properly supported just a year ago for the majority of browsers. Reference: https://caniuse.com/#search=SameSite https://caniuse.com/#search=SameSite