0
votes

i'm implementing csurf middlware to prevent CSRF attacks. I don't understand why I've to store the token generated in a cookie:

csurf({ cookie: {
    sameSite: true,
    httpOnly: true
}})

when I can render the value in a hidden input and then receive it back in the payload of the POST request.

res.render("registration", {csrfToken: req.csrfToken()});
<input type="hidden" name="_csrf" value="{{csrfToken}}">
1

1 Answers

0
votes

The cookie usage allows you to use CSRF for JavaScript implementations (i.e. if you're using React or Angular or Vue you can read the CSRF value out of the cookie and send it back as a request parameter or header).