3 ms·
What I don't understand is why store it server side? If we make a HTTP Only + secure cookie containing the encrypted and signed csrf value, it can't be obtained
by tebruno99 6y ago
What I don't understand is why store it server side? If we make a HTTP Only + secure cookie containing the encrypted and signed csrf value, it can't be obtained by an attacker & the server would require no state or shared cache between instances. It would just compare the HTTP only cookie to the value submitted with the form. On response, expire that cookie.
Does anyone know of a downside to that?
- bluepnume 6y agoYup. This is known as 'double submit'. https://cheatsheetseries.owasp.org/cheatsheets/Cross-Site_Request_Forgery_Prevention_Cheat_Sheet.html#double-submit-cookie https://cheatsheetseries.owasp.org/cheatsheets/Cross-Site_Re...
- tebruno99 6y agoAh! Thanks, I've been looking for the exact definition!