> For the complete documentation index, see [llms.txt](https://newrouge.gitbook.io/roguebook1/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://newrouge.gitbook.io/roguebook1/group/web/csrf.md).

# CSRF

### samesite vs sameorigin

{% embed url="<https://jub0bs.com/posts/2021-01-29-great-samesite-confusion/>" %}

{% embed url="<https://portswigger.net/web-security/csrf/bypassing-samesite-restrictions>" %}

from mozilla

The possible attribute values are:

[`Strict`](https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/Set-Cookie#strict)

Send the cookie only for requests originating from the same [site](https://developer.mozilla.org/en-US/docs/Glossary/Site) that set the cookie.

[`Lax`](https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/Set-Cookie#lax)

Send the cookie only for requests originating from the same [site](https://developer.mozilla.org/en-US/docs/Glossary/Site) that set the cookie, and for cross-site requests that meet both of the following criteria:

* The request is a top-level navigation: this essentially means that the request causes the URL shown in the browser's address bar to change.
  * This would exclude, for example, requests made using the [`fetch()`](https://developer.mozilla.org/en-US/docs/Web/API/Window/fetch) API, or requests for subresources from [`<img>`](https://developer.mozilla.org/en-US/docs/Web/HTML/Reference/Elements/img) or [`<script>`](https://developer.mozilla.org/en-US/docs/Web/HTML/Reference/Elements/script) elements, or navigations inside [`<iframe>`](https://developer.mozilla.org/en-US/docs/Web/HTML/Reference/Elements/iframe) elements.
  * It would include requests made when the user clicks a link in the top-level browsing context from one site to another, or an assignment to [`document.location`](https://developer.mozilla.org/en-US/docs/Web/API/Document/location), or a [`<form>`](https://developer.mozilla.org/en-US/docs/Web/HTML/Reference/Elements/form) submission.
* The request uses a [safe](https://developer.mozilla.org/en-US/docs/Glossary/Safe/HTTP) method: in particular, this excludes [`POST`](https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Methods/POST), [`PUT`](https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Methods/PUT), and [`DELETE`](https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Methods/DELETE).

Some browsers use `Lax` as the default value if `SameSite` is not specified: see [Browser compatibility](https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/Set-Cookie#browser_compatibility) for details.

**Note:** When `Lax` is applied as a default, a more permissive version is used. In this more permissive version, cookies are also included in [`POST`](https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Methods/POST) requests, as long as they were set no more than two minutes before the request was made.

[`None`](https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/Set-Cookie#none)

Send the cookie with both cross-site and same-site requests. The `Secure` attribute must also be set when using this value.
