CSRF Protection
Kind: mechanism
Layer: Security Core
Aliases: Cross-Site Request Forgery Protection
Record: architecture:csrf-protection
Severity: contextual
Scope: service, web, security
Canonical: Ontology
A mechanism that rejects state-changing requests which lack proof of coming from the site's own pages, such as an anti-forgery token.
Listed in Architecture principles, after Continuous Compliance and before Parameterized Queries.