Skip to content

Archive

CSRF

13 articles
Cybersecurity 23 Sep 2026 5 min read

Fetch Metadata Adds Request Context to Server-Side Policy

Fetch Metadata Adds Request Context to Server-Side Policy A server often sees the same authenticated cookie on requests created by very different browser actions. A form submitted from another site, a same-origin API call, an image load, and a top-level navigation can all reach the same host. Cookies alone do not describe that request context. Fetch Metadata adds browser-generated request headers that describe where a request came from and how the browser intends to use the response. A server can incorporate those signals into an isolation policy before application logic handles a sensitive route.

Cybersecurity 22 Sep 2026 5 min read

SameSite Cookies Constrain Cross-Site Credential Sending

SameSite Cookies Constrain Cross-Site Credential Sending Cookies are ambient credentials: once a browser stores a cookie that matches a request’s domain, path, security, and expiry rules, application code does not have to add that cookie explicitly to every request. That convenience also creates a security boundary. A page on one site can cause a browser to send requests to another site, and some of those requests may carry cookies. The SameSite attribute gives the browser another condition to evaluate before attaching a cookie. It does not change the cookie’s value or authenticate the request by itself. It controls cookie inclusion according to the relationship between the request context and the cookie’s site.

Cybersecurity 21 Sep 2026 5 min read

SameSite Cookies Constrain Cross-Site Session Sending

SameSite Cookies Constrain Cross-Site Session Sending A session cookie is an ambient credential: once stored, the browser can attach it to matching HTTP requests without application code copying the value into each request. That convenience also creates a security boundary. A request initiated from another site can reach an application while carrying the user’s authenticated session unless cookie policy prevents it. The SameSite attribute gives the browser a rule for deciding whether a cookie may accompany a request in a cross-site context. It does not change the cookie value or authenticate the request by itself. It changes when the browser includes that cookie.

Cybersecurity 21 Sep 2026 5 min read

Fetch Metadata Headers Filter Cross-Site Requests

Fetch Metadata Headers Filter Cross-Site Requests A web server often receives requests that look valid at the HTTP layer even when they originated from an unrelated site. Cookies may accompany those requests, and a state-changing endpoint can be exposed if its defenses treat every browser request as equally trustworthy. Fetch Metadata gives the server additional context. Supporting browsers attach Sec-Fetch-* request headers that describe the relationship between the initiator and target, the request mode, the destination, and whether navigation resulted from direct user activation. A server can use that context as an early resource-isolation gate.

Cybersecurity 20 Sep 2026 6 min read

SameSite Cookies Reduce Cross-Site Request Attachment

SameSite Cookies Reduce Cross-Site Request Attachment Cookie-based sessions rely on browser behavior that is both useful and security-sensitive: once a cookie matches a request’s domain, path, security, and other applicable rules, the browser can attach it without application code explicitly supplying the credential. That ambient behavior makes sessions convenient, but it also creates a channel through which a request initiated from another site can arrive with authentication state. The SameSite cookie attribute narrows that channel. It tells the browser whether a cookie may accompany requests whose site context differs from the cookie’s site. The control changes credential attachment at the browser boundary; it does not turn a state-changing endpoint into an authorized operation by itself.

Cybersecurity 20 Sep 2026 6 min read

Fetch Metadata Headers Gate Cross-Site Requests

Fetch Metadata Headers Gate Cross-Site Requests A web server often receives enough HTTP information to route a request but not enough to tell what browser context produced it. A GET might be a top-level navigation, an image load, or a JavaScript fetch. A POST might come from the application’s own page or from a form hosted on another site. Fetch Metadata adds browser-generated request headers that describe that context. Sec-Fetch-Site reports the relationship between the initiator and target, while Sec-Fetch-Mode, Sec-Fetch-Dest, and in some cases Sec-Fetch-User describe the request mode, destination, and user activation. A server can use those signals to reject request shapes that an endpoint has no reason to accept.

Cybersecurity 17 Sep 2026 6 min read

SameSite Cookies Enforce a Site Boundary, Not an Origin Boundary

SameSite Cookies Enforce a Site Boundary, Not an Origin Boundary An application at https://accounts.example.com uses a session cookie marked SameSite=Strict. A separate service at https://reports.example.com is operated by another team and has a distinct origin. The two hosts are isolated by the browser’s origin model for many web capabilities, yet a request from one can still be classified as same-site with the other. The cookie attribute is enforcing a site boundary, not duplicating the same-origin policy.

Cybersecurity 16 Sep 2026 7 min read

SameSite Cookies Draw a Site Boundary That Is Broader Than Origin

SameSite Cookies Draw a Site Boundary That Is Broader Than Origin Two HTTPS applications can be isolated by the browser’s same-origin policy yet still occupy the same cookie site. A service at accounts.example.com and another at shop.example.com have different origins because their hosts differ, but cookie policy can classify their request context at a broader site boundary. That gap matters when SameSite is treated as if it were equivalent to origin isolation.

Cybersecurity 16 Sep 2026 7 min read

Fetch Metadata Lets Servers Reject Cross-Site Request Contexts

Fetch Metadata Lets Servers Reject Cross-Site Request Contexts An authenticated endpoint can receive a syntactically valid request carrying ambient credentials even when the navigation or resource load began on another site. Cookies alone do not tell the server what browser context produced the request. Fetch Metadata adds request headers that expose selected context already known to the user agent, giving the server another signal before it accepts a state-changing operation or serves a sensitive resource.

Cybersecurity 15 Sep 2026 5 min read

SameSite Cookies Move CSRF Control Into Request Context

A browser can send an authenticated request that the account holder never intended to initiate. The target site may receive a valid session cookie, see a legitimate account, and process a state change even though the request originated from another site. The credential is ambient: browser attachment, not explicit application code, supplies it. The SameSite cookie attribute changes that attachment decision. Rather than asking the server to distinguish hostile requests after every cookie arrives, it gives the user agent policy for deciding whether a cookie accompanies requests in cross-site contexts. That moves part of the CSRF boundary into browser request processing, but only for cookies covered by the attribute and only according to the site’s relationship and request context defined by browser policy.

Cybersecurity 15 Sep 2026 6 min read

Fetch Metadata Makes Cross-Site Request Context Visible

Fetch Metadata Makes Cross-Site Request Context Visible A server receiving an authenticated HTTP request often sees valid cookies, a plausible path, and a method that the application accepts. Those facts do not reveal whether the request began inside the application’s own page or was triggered by a document on another site. For endpoints that change state, that missing context has long been central to cross-site request forgery defenses. Fetch Metadata request headers expose part of the context already known to the browser. Headers such as Sec-Fetch-Site, Sec-Fetch-Mode, Sec-Fetch-Dest, and Sec-Fetch-User describe relationships and properties surrounding a request. A server can use those signals to reject request patterns that do not belong to its application architecture.

Cybersecurity 14 Sep 2026 6 min read

SameSite Cookies Bound Cross-Site Credential Sending

SameSite Cookies Bound Cross-Site Credential Sending A browser can send an authenticated request that the account holder never intended to make. The application may see a valid session cookie, a normal HTTP method, and a request arriving over TLS. None of those facts proves that the request originated from a page the application trusts. That gap is central to cross-site request forgery. Cookie-based sessions are ambient credentials: once stored, they can be attached by the browser according to cookie rules rather than by deliberate application code at each request. The SameSite attribute changes those rules by restricting cookie attachment in cross-site contexts.

Cybersecurity 02 Sep 2026 5 min read

Practical CSRF Defense with SameSite Cookies and Tokens

Cross-site request forgery (CSRF) abuses the fact that browsers can automatically attach a user’s cookies to requests. If a state-changing endpoint trusts only the presence of an authenticated cookie, another site may be able to trigger that endpoint from the user’s browser. Modern cookie controls reduce the attack surface, but robust applications still need to reason about request semantics and trust boundaries. Understand the condition that makes CSRF possible A typical CSRF attack needs three ingredients: