Add CSRF protection to a form
csrf-no-protection
A state-changing form with no CSRF token can be submitted from any other site using the visitor's own cookies. Add a token and check it server side.
Frameworks
Next.js
- 1 For Server Actions, Next.js handles CSRF automatically
- 2 For API routes, use SameSite cookies and validate the Origin header
typescript
// API route CSRF check
export async function POST(request) {
const origin = request.headers.get('origin');
if (origin !== process.env.NEXT_PUBLIC_URL) {
return new Response('Forbidden', { status: 403 });
}
// ...
}Does your app still have this?
Scan your domain