Uh oh!
There was an error while loading.Please reload this page.
- Notifications
You must be signed in to change notification settings - Fork9.6k
Closed
Description
From the discussion in#18115 :
we should add the Double Submit Cookies CSRF prevention strategy as described by
https://www.owasp.org/index.php/CSRF_Prevention_Cheat_Sheet#Double_Submit_Cookies
If doable, this should be the default CSRF prevention strategy used in symfony SE