backend · medium
CSRF
Cross-Site Request Forgery — a browser sends a victim’s cookies to your site from another origin; tokens or SameSite mitigate it.
Where you see it
Rails form helpers emit an authenticity token; `protect_from_forgery` checks it on non-GET requests. Cookie-session apps need this; bearer-token JSON APIs often use a different story.
Why it matters
CSRF is a classic web security question. Naming tokens vs SameSite vs CORS (a different problem) shows you have shipped authenticated HTML forms, not only toy JSON APIs.
Tags: rails, nodejs
