Facebook Pixel The Right Ways to Address Cross-Site Request Forgery | Open Source For You - technology - Les denne historien på Magzter.com

Prøve GULL - Gratis

The Right Ways to Address Cross-Site Request Forgery

Open Source For You

|

June 2025

Here’s an overview of the key concepts, impact and effective mitigation strategies of cross-site request forgery, also known as CSRF.

- Sanjay Phanshikar and Divyasri Thota

The Right Ways to Address Cross-Site Request Forgery

CSRF (cross-site request forgery) was included in the OWASP (Open Worldwide Application Security Project) Top 10 list in 2013 but was removed from it in 2017 as the statistical data did not justify its place there. However, CSRF still impacts web applications a great deal.

The effect of a CSRF exploit varies from case to case. There are multiple factors that decide the severity of the exploit, which could be:

  • Unauthorised actions [money transfer, account setting changes]

  • Privilege escalation [admin access]

  • Application integrity and confidentiality loss [data theft]

  • Possible loss of reputation [negative image within users or communities]

SOP (Same-Origin Policy)

To understand why CSRF is successful, one needs to understand the Same-Origin Policy (SOP) used by browsers. The latter follow SOP by default and only allow requests from the same origin. However, there is a business need for the user to make a cross-origin or cross-domain request to the application server. There are a lot of security concerns around allowing cross-domain requests. Initially, browser implementations used CORS (cross-origin resource sharing) to accommodate cross-domain requests while taking security concerns into consideration. Recent implementations have come up with a cookie attribute called ‘SameSite’. Let us discuss CORS and SameSite in brief.

imageTo address the need of cross-origin requests, CORS specifications are used, and browsers are made compliant with CORS specs. Application servers explicitly whitelist the trusted domains from where they can accept cross-origin requests and browsers are directed accordingly, using CORS-specific response headers.

FLERE HISTORIER FRA Open Source For You

Open Source For You

Open Source For You

Sending IoT Sensor Data to Public or Private Servers

This IoT system shows a simple and effective way to send sensor data using an ESP8266 microchip.

time to read

3 mins

March 2026

Open Source For You

Open Source For You

Popular FOSS Tools for LLM Observability, Monitoring and Evaluation

This overview of popular tools for monitoring large language models also sheds light on how LLM-as-a-judge enhances their performance.

time to read

2 mins

March 2026

Open Source For You

Open Source For You

Data Deduplication Done the Right Way

Deduplication helps to save space on Linux-based storage systems. Choose the right platform and check whether it meets your goals.

time to read

6 mins

March 2026

Open Source For You

Open Source For You

The Relevance of Rubber Duck Debugging in the Age of AI

Discover why rubber duck debugging is a powerful process today. There's also a step-by-step guide on how to use it in the age of artificial intelligence.

time to read

4 mins

March 2026

Open Source For You

Open Source For You

GitHub weighs turning off pull requests as AĬ slop floods projects

GitHub has formally acknowledged that AI-generated 'slop' is overwhelming open source projects, forcing maintainers to sift through poor pull requests (PRS), abandoned submissions and guideline violations - and is now considering restricting or even disabling pull requests, the core mechanism of open collaboration.

time to read

1 min

March 2026

Open Source For You

Open Source For You

Global banks are deploying Ethereum's Layer-2 stack

Banks are standardising on Ethereum's open source stack as production financial infrastructure, shifting from experimental pilots and proprietary blockchains to live Layer-2 networks for tokenised deposits, interbank payments, and cross-border settlement.

time to read

1 min

March 2026

Open Source For You

Open Source For You

OpenClaw's creator joins OpenAl

In a move that reinforces its commitment to open development rather than acquisition, OpenAI has brought Peter Steinberger, founder of OpenClaw, into the company while placing the popular AI agent under a foundation structure to ensure it remains open source.

time to read

1 min

March 2026

Open Source For You

LibreOffice 26.2 comes with native Markdown support

LibreOffice 26.2 has been released by The Document Foundation, strengthening its position as a fully free and open source office suite for Windows, macOS, and Linux, with support for more than 120 languages.

time to read

1 min

March 2026

Open Source For You

Open Source For You

Indian government mandates labelling of Al-generated content and quicker deletion of illegal deepfakes

India has introduced sweeping AI content rules that immediately place pressure on social platforms and open source AI ecosystems to label, trace and rapidly remove AI Open ource synthetic media at scale.

time to read

1 min

March 2026

Open Source For You

Open Source For You

I2C and I3C: How Modern Devices Communicate

I3C and I2C are both two-wire communication protocols that help exchange data between multiple devices. While I3C preserves the simplicity of I2C, it introduces new features suited for today's sensor-rich devices.

time to read

8 mins

March 2026

Listen

Translate

Share

-
+

Change font size