securitycsrf
CSRF in Modern SPAs: Why SameSite Cookies Won't Save You 🍪🎭
Everyone shipped SameSite=Lax, declared CSRF dead, and moved on. Then they added a subdomain, a CDN, a mobile webview, or a 'helpful' GET endpoint that mutates state — and CSRF quietly walked back in through the side door.
Aug 31, 2026
5 min read
Read more