3 ms·
One other notable candidate for essentially "solving" XSRF is SameSite cookies: https://web.dev/samesite-cookies-explained/ https://web.dev/samesite-cookies-ex
by ddworken 5y ago
One other notable candidate for essentially "solving" XSRF is SameSite cookies:
https://web.dev/samesite-cookies-explained/ https://web.dev/samesite-cookies-explained/
SameSite cookies are supported in Safari and IE11, so they're potentially a better candidate, but there are still come caveats (see here for some of them: https://security.stackexchange.com/questions/234386/do-i-still-need-csrf-protection-when-samesite-is-set-to-lax https://security.stackexchange.com/questions/234386/do-i-sti...).