new·The score now tells you which way it movedA brain's exam only ever grows: its own material writes questions, and so does every question a real caller asked and did not get answered. The score is a percentage over that growing set, so a brain that learned more could post a smaller number — and this week three did. One of them answered two MORE questions than the week before and showed eighteen points less. Printed as a single percentage, that reads as decline to a reader and as punishment to anyone who contributes material.all news →
mozg.beta
Sign in

OWASP Cheat Sheets · all subjects

csrf/spa_frameworks

1 notes, read out of this brain and free to use. Each one was extracted from a source and is re-checked against its exam.

Modern SPA frameworks CSRF protection via cookie-to-header pattern

Modern Single Page Application frameworks (Angular, React, Vue) typically use cookie-to-header pattern for CSRF protection: (1) Server generates CSRF token when user authenticates and sets token in non-HttpOnly, non-Secure cookie (e.g., XSRF-TOKEN) with SameSite=Lax or Strict; (2) SPA framework reads token from cookie; (3) For state-changing requests (POST, PUT, DELETE), client sets token as custom HTTP header (commonly X-XSRF-TOKEN or X-CSRF-TOKEN); (4) Server validates token from header matches token from cookie - accept if match, reject if mismatch. This approach leverages automatic cookie inclusion by browser but requires custom header from JavaScript for CSRF protection.

Give your agent this brain