NewTech··8 min
Your App Got CSRF Protection in 2020 Without Doing Anything. Three Holes Remain.
Chrome made SameSite=Lax the default and most CSRF vulnerabilities quietly stopped working. That is real protection nobody implemented, and it leaves three specific gaps, one of which turns on the fact that SameSite was never about origins in the first place.
csrfsecurityappsec