freecoding.school100% FREE · NO SIGNUP
Endpoint BayISSUE #43 of 45

csrf · same-site · double submit

RestaVSThe 401 Bandit
Resta saysCSRF tricks a logged-in browser into making unwanted requests — defend with SameSite and tokens.

Because browsers auto-send cookies, a malicious site can make your browser fire an authenticated request to your bank (Cross-Site Request Forgery). Defenses: SameSite cookies (block cross-site sends), anti-CSRF tokens (a secret the attacker can't know), and checking the Origin/Referer. Token-based (Authorization header) APIs are largely immune since the header isn't auto-sent.

Power-ups you unlock

The 401 Bandit attacks — common mistakes

Boss battleExplain why bearer-token APIs are mostly immune to CSRF.

Example code

<!doctype html><html><head><meta charset="utf-8"></head>
<body style="background:#06040d;color:#e6e0ff;font-family:monospace;padding:20px"><pre>cookies: auto-sent → CSRF possible → SameSite + token
Authorization: Bearer ... : NOT auto-sent → immune</pre></body></html>
▶ Open the interactive comic issue
‹ Session Cookies · Server-Managed SessionsCors · Cross-Origin Requests ›