All fixes

Add CSRF protection to a form

csrf-no-protection

A state-changing form with no CSRF token can be submitted from any other site using the visitor's own cookies. Add a token and check it server side.

Next.js

  1. 1 For Server Actions, Next.js handles CSRF automatically
  2. 2 For API routes, use SameSite cookies and validate the Origin header
typescript
// API route CSRF check
export async function POST(request) {
  const origin = request.headers.get('origin');
  if (origin !== process.env.NEXT_PUBLIC_URL) {
    return new Response('Forbidden', { status: 403 });
  }
  // ...
}

Does your app still have this?

Scan your domain