Avoiding XSS
Synchronizer Tokens
<form>
<input type=“text” name=“login”></input>
<input type=“password” name=“password”></input>
<input type="hidden" name="csrf_token" value="KbyUmhTLMpYj7CD2di7JKP1P3qmLlkPt"/>
</form>Cookie-to-header
SameSite cookie attribute
Double cookie submission
Last updated