logoalt Hacker News

nchmytoday at 6:22 AM1 replyview on HN

Client side js is not particularly relevant to csrf.


Replies

tptacektoday at 6:32 AM

I mostly agree, but that's the logic OWASP uses to argue you should still be doing explicit tokens even if you're using SameSite and Sec-Fetch.

show 1 reply