Slide 7
Slide 7 text
Double-Submit Cookie Pattern
Reference: https://owasp.org/www-pdf-archive/David_Johansson-Double_Defeat_of_Double-Submit_Cookie.pdf
Browser
Request
🍪
Cookie with CSRF Token
📩
CSRF Token in
Request
⚖
Do they match?
Request domain == Cookie domain
Browser sends the cookies
Browser does not add the CSRF Token in
the request