1. Executive Summary & CSRF Attack Mechanics
Cross-Site Request Forgery (CSRF) is an attack that forces an authenticated end-user to execute unwanted, state-changing actions on a trusted web application. When a victim visits a malicious site, the adversary's page triggers an HTTP request (via hidden forms, fetch calls, or images) to the vulnerable application. Because the victim's browser automatically attaches existing session cookies, the server executes the action under the victim's identity.
2. Multi-Layered CSRF Defense Architecture
Modern web security mandates two complementary layers of defense: Cryptographic Anti-CSRF Tokens and SameSite Cookie Enforcements.
A. Synchronizer Token Pattern (STP) - PHP Implementation
Generate a unique, cryptographically random, unpredictable token stored in the server session and injected into forms as a hidden field:
B. Modern Cookie Hardening: SameSite Flags
Configure session cookies to block transmission on cross-origin requests:
| SameSite Setting | Top-Level Navigation (e.g. clicking link) | Cross-Site POST (Form / Fetch) | Security Profile |
|---|---|---|---|
| Strict | Blocked | Blocked | Maximum protection; user appears logged out if clicking link from email. |
| Lax (Recommended) | Allowed | Blocked | Standard balance; safe against all cross-site POST attacks. |
| None | Allowed | Allowed | Permits cross-site requests; requires Secure flag. High CSRF risk. |
3. Securing Single-Page Apps (SPA) & REST APIs
For asynchronous fetch() or Axios requests, pass the CSRF token via standard HTTP headers (e.g., X-CSRF-Token or X-XSRF-Token):
4. CSRF Defense Audit Checklist
| Audit Check | Compliance Standard | Pass Criteria |
|---|---|---|
| State-Changing Methods | GET, HEAD, and OPTIONS requests must be strictly idempotent (never modify state). | Zero state mutations triggered via GET query parameters. |
| Token Randomness | Generated via cryptographically secure pseudo-random number generator (CSPRNG). | Minimum 128-bit entropy (e.g. 32-byte hex). |
| Constant-Time Verification | Token comparison executes via hash_equals(). |
Zero susceptibility to string comparison timing attacks. |
| Cookie Hardening | Session cookies marked with SameSite=Lax (or Strict), Secure, and HttpOnly. |
Verified via browser DevTools Application tab. |
WebOTG Standards Directorate
WebOTG provides benchmark reference documentation, automated matrix evaluators, and security test harnesses for government digital platforms, WQMS architectures, and STQC compliance frameworks.