backend · medium

CSRF

Cross-Site Request Forgery — a browser sends a victim’s cookies to your site from another origin; tokens or SameSite mitigate it.

Where you see it

Rails form helpers emit an authenticity token; `protect_from_forgery` checks it on non-GET requests. Cookie-session apps need this; bearer-token JSON APIs often use a different story.

Why it matters

CSRF is a classic web security question. Naming tokens vs SameSite vs CORS (a different problem) shows you have shipped authenticated HTML forms, not only toy JSON APIs.

Tags: rails, nodejs