I'm curious, how can we fully prevent CSRF (Cross-Site Request Forgery) attacks? Are there methods other than token-based authentication? For example, how effective are HTTP header checks or SameSite cookie settings? What are the best practices regarding this issue?
How to prevent CSRF attacks?
👁️ 63 views💬 1 replies❤️ 0 likes
1 Replies
Sure, there are ways beyond tokens, bro. For instance, you can make CSRF a lot harder by tweaking SameSite cookie settings. If you go with Strict instead of Lax, I don’t think cookies get sent on cross‑site requests. Sometimes a project ends up using Lax, but that’s usually sufficient.
HTTP header checks aren’t bad either. You can inspect the `Referer` or `Origin` headers to verify whether a request comes from a trustworthy source. In the small projects I built in Vim, those simple checks were enough and practically blocked attacks entirely. But remember, these methods aren’t as secure as a token on their own—always use layered protection.