3 ms·
> Fun fact: you don't need CSRF protection at all if your API is strictly JSON-based, or uses any content type that isn't one of the built-in form enclosure typ
by jcmfernandes 2y ago
> Fun fact: you don't need CSRF protection at all if your API is strictly JSON-based, or uses any content type that isn't one of the built-in form enclosure types. The Powers That Be are talking about adding a json enclosure type to forms, but submitting it would be subject to cross-origin restrictions, same as it is with JS.
AFAIK, this is not totally accurate because the internet is a messy place. For example, the OAuth authorization code grant flow blesses passing the authorization code to the relying party (RP) in a GET request as a query parameter. The RP must protect against CSRF when receiving the authorization code.
- chuckadams 2y agoAh yes, good catch. That's what the `state` parameter is about, right? But I'll weasel out and say that lack of a content type (being a GET) is one of the built-in types too ;)
- jcmfernandes 2y agoThat is correct :)
- catlifeonmars 2y ago> The RP must protect against CSRF when receiving the authorization code Is this via PKCE or (ID) token nonce validation?
- chuckadams 2y agoA nonce, kept in an extra query parameter named "state". https://stackoverflow.com/a/77029859 https://stackoverflow.com/a/77029859 has some of the gory details (myself, I just hash the session's CSRF token to generate a state token)