Explain CSRF on a cookie-based session SPA and how you mitigate it.
PICTURE THIS: A SENTENCE BECOMES TOKENS
The model does not read letters like humans. It reads these pieces, then predicts the next one.
Simple meaning
A malicious site can POST to my API and the browser attaches SameSite-None cookies.
WHY — Security instead of guessing?
Why interviewers care about Security:
who only read docs from people who shipped.
and tied to Frontend work.
Name the idea, why it exists, then one short example.
End with when you use it and one common pitfall.
STEPS — What happens with tokens?
Before the model can read a sentence, it goes through these steps:
- 1A malicious site can
POST to my API and the browser attaches SameSite-None cookies.
- 2I use SameSite Lax,
CSRF tokens, and avoid state-changing GET.
- 3For bearer tokens in
memory plus a refresh cookie, I still treat CORS and CSRF as separate discussions.
- 4Context mix
Attention looks at nearby tokens together.
- 5Next token
The model scores what should come next.
- 6Decode
IDs turn back into readable text.
EXAMPLE — See it in action
Let's see how a real sentence is tokenized (tokens may vary by model):
Note: Actual tokens and IDs depend on the tokenizer (e.g., GPT, Llama, etc.).
Key takeaway
A malicious site can POST to my API and the browser attaches SameSite-None cookies. I use SameSite Lax, CSRF tokens, and avoid state-changing GET.