Skip to content

CSRF protection for cookie-based refresh #2075

@geolunalg

Description

@geolunalg

Overview

User Story:
As a system, I want to prevent CSRF attacks on endpoints that rely on cookies.

Action Items

Acceptance Criteria:

  • Refresh/logout endpoints are protected by:
    • SameSite cookie settings and/or
    • CSRF token (double submit or header-based)
  • Backend rejects refresh requests missing CSRF proof (if implemented).

Resources/Instructions

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    Status

    New Issue Approval

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions