3 ms·
The CSRF token is usually stored in a cookie. I guess one could try stealing the cookie assuming the CSRF token hasn't been consumed. But if one's cookie happe
by theogravity 2y ago
The CSRF token is usually stored in a cookie. I guess one could try stealing the cookie assuming the CSRF token hasn't been consumed.
But if one's cookie happens to be stolen it can be assumed they already have access to your session in general anyways making CSRF moot.