Lazo Lab Sign up

Web Security / Sessions and logins

Lesson 14 of 27

CSRF

Cross-site request forgery tricks your browser into submitting a form to a site you're logged in to. A secret CSRF token in each form stops it.

Key points

  • Add a random token to every form
  • Check it on the server
  • SameSite cookies help too
<input type="hidden" name="csrf" value="{{ csrf_token() }}">
Watch a video on thisOpens YouTube search results for “CSRF” in a new tab

Quiz · +10 XP

What stops CSRF attacks?

Log in to save progress and earn XP.