Skip to main content
One idea at a time

Cookies make browser trust a server concern

Browsers attach eligible cookies automatically. That convenience also creates a problem: another website may cause a browser to submit a request using an existing session.

Cross-site request forgery, or CSRF, is a request made through a victim's browser that performs an action using the victim's ambient credentials. The attack does not require knowing the cookie value.

Taskboard requires a CSRF token for authenticated writes. Authentication responses provide the token, and the frontend sends it in a header.

PATCH /api/workspaces/workspace-id/tasks/task-id HTTP/1.1
X-CSRF-Token: token-from-the-auth-response
Content-Type: application/json

{"status":"done","expectedVersion":4}

The cookie identifies the session. The header demonstrates possession of the session's CSRF secret through an allowed application flow. An unrelated website must not be able to read that secret.

CORS governs cross-origin browser access​

An origin combines scheme, host, and port. A frontend at one origin calling an API at another may need Cross-Origin Resource Sharing, or CORS.

CORS tells the browser which origins may read responses and which cross-origin request arrangements are allowed. Credentialed requests need an explicit allowed origin and appropriate client settings. A wildcard origin is incompatible with credentialed response access.

CORS does not stop a non-browser client from calling the API. It also does not replace authorization. An allowed frontend origin can still send a task identifier belonging to another workspace.

Some cross-origin requests can be sent even when the browser prevents the calling page from reading the response. That is why a CORS policy alone is not a complete CSRF defense.

SameSite cookies provide additional browser restrictions. Their behavior depends on whether a request is same-site, which differs from same-origin. The application keeps explicit CSRF checks rather than assuming every deployment shares the same origin arrangement.

Route purpose matters​

Stripe webhooks do not use Maya's cookie or CSRF token. They authenticate with a provider signature. Applying the browser's CSRF requirement to that endpoint would reject legitimate provider events.

Can CORS protect an API from a command-line HTTP client?

No. CORS is a browser policy. The API must authenticate and authorize callers regardless of the software making the request.

Cookies identify a session, CSRF protects browser-authenticated writes, and CORS governs cross-origin browser access. Each answers a different question.

Read api/src/app.ts Read api/src/auth.ts