CSRF

samesite vs sameorigin

from mozilla

The possible attribute values are:

Strictarrow-up-right

Send the cookie only for requests originating from the same sitearrow-up-right that set the cookie.

Laxarrow-up-right

Send the cookie only for requests originating from the same sitearrow-up-right that set the cookie, and for cross-site requests that meet both of the following criteria:

Some browsers use Lax as the default value if SameSite is not specified: see Browser compatibilityarrow-up-right for details.

Note: When Lax is applied as a default, a more permissive version is used. In this more permissive version, cookies are also included in POSTarrow-up-right requests, as long as they were set no more than two minutes before the request was made.

Nonearrow-up-right

Send the cookie with both cross-site and same-site requests. The Secure attribute must also be set when using this value.

Last updated