Security · Multiple choice

Why is an app that authenticates with a session cookie exposed to CSRF, while one that sends a bearer token in the Authorization header is not?

medium

Options

Why

A malicious page can submit a form to your site, and the browser adds your cookie. A header must be set by your own page's script, which other origins cannot do. Defend cookie sessions with SameSite, a CSRF token on state-changing requests, and never changing state on GET.

Review this in your daily deck All cards in Security