CSRF Protection

Kind: mechanism

Layer: Security Core

Aliases: Cross-Site Request Forgery Protection

Record: architecture:csrf-protection

Severity: contextual

Scope: service, web, security

Canonical: Ontology

A mechanism that rejects state-changing requests which lack proof of coming from the site's own pages, such as an anti-forgery token.

Listed in Architecture principles, after Continuous Compliance and before Parameterized Queries.

Requires

Reinforces

Enables

Conflicts with

In tension with

Tensions

Violated by

Severity

Category

Linked from