9 ms·
I don't understand what you are getting at. CSRF is not another name for auth. You always need auth, CSRF is a separate problem. When the browser sends a reque
by hmry 1y ago
I don't understand what you are getting at. CSRF is not another name for auth. You always need auth, CSRF is a separate problem.
When the browser sends a request to your server, it includes all the cookies for your domain. Even if that request is coming from a <form> or <img> tag on a different website you don't control. A malicious website could create a form element that sends a request to yourdomain.com/api/delete-my-account and the browser would send along the auth cookie for yourdomain.com.
A cookie only proves that the browser is authorized to act on behalf of the user, not that the request came from your website. That's why you need some non-cookie way to prove the request came from your origin. That's what Sec-Fetch-Site is.