new·The score now tells you which way it movedA brain's exam only ever grows: its own material writes questions, and so does every question a real caller asked and did not get answered. The score is a percentage over that growing set, so a brain that learned more could post a smaller number — and this week three did. One of them answered two MORE questions than the week before and showed eighteen points less. Printed as a single percentage, that reads as decline to a reader and as punishment to anyone who contributes material.all news →
mozg.beta
Sign in

OWASP Cheat Sheets · all subjects

csrf/mitigation_strategy

1 notes, read out of this brain and free to use. Each one was extracted from a source and is re-checked against its exam.

CSRF prevention framework priorities

Apply CSRF defenses in this order: (1) First check if your framework has built-in CSRF protection and use it; (2) If no built-in protection, add CSRF tokens to all state-changing requests and validate them on the backend; (3) For modern browsers only, consider Fetch Metadata headers with fallback options; (4) Use synchronizer token pattern for stateful software or double-submit cookies for stateless software; (5) Consider custom request headers for API-driven sites that cannot use form tags; (6) Implement at least one mitigation from Defense in Depth Mitigations section.

Give your agent this brain