High Security Question 164 of 229

Explain CSRF on a cookie-based session SPA and how you mitigate it.

Frontend Master · Speak this in 60–90 seconds · Faridabad & Delhi NCR

PICTURE THIS: A SENTENCE BECOMES TOKENS

The model does not read letters like humans. It reads these pieces, then predicts the next one.

Simple meaning

A malicious site can POST to my API and the browser attaches SameSite-None cookies.

1

WHY — Security instead of guessing?

Why interviewers care about Security:

Security questions separate people

who only read docs from people who shipped.

Keep it short, concrete,

and tied to Frontend work.

Stay structured

Name the idea, why it exists, then one short example.

Close cleanly

End with when you use it and one common pitfall.

2

STEPS — What happens with tokens?

Before the model can read a sentence, it goes through these steps:

  1. 1
    A malicious site can

    POST to my API and the browser attaches SameSite-None cookies.

  2. 2
    I use SameSite Lax,

    CSRF tokens, and avoid state-changing GET.

  3. 3
    For bearer tokens in

    memory plus a refresh cookie, I still treat CORS and CSRF as separate discussions.

  4. 4
    Context mix

    Attention looks at nearby tokens together.

  5. 5
    Next token

    The model scores what should come next.

  6. 6
    Decode

    IDs turn back into readable text.

3

EXAMPLE — See it in action

Let's see how a real sentence is tokenized (tokens may vary by model):

Input text
“I use SameSite Lax, CSRF tokens, and avoid state-changing GET.”
Tokenized output
IuseSameSiteLaxCSRFtokens
Token IDs (example)
2987408337471632900

Note: Actual tokens and IDs depend on the tokenizer (e.g., GPT, Llama, etc.).

Key takeaway

A malicious site can POST to my API and the browser attaches SameSite-None cookies. I use SameSite Lax, CSRF tokens, and avoid state-changing GET.

Chat with us