3 ms·
There is certainly less need for it now as browsers have many more mitigations in place than when CSRf was first introduced. But I would say yes you still need
by diroussel 5y ago
There is certainly less need for it now as browsers have many more mitigations in place than when CSRf was first introduced.
But I would say yes you still need it for defence in depth.
For instance in RFC6749 (OAuth 2.0) it says clients MUST implement CSRF for the redirection step.