Building CSRF Double-Submit Cookie Protection in PHP Video Admin Panels

php dev.to

A forged POST that purged our entire CDN cache Last spring I watched the LiteSpeed page-cache hit ratio on DailyWatch fall off a cliff for twenty minutes. Nothing had deployed. No cron had fired. What actually happened was dumber and scarier than any of that: a bookmarked browser tab, still logged into our admin panel, loaded an unrelated forum page, and that page auto-submitted a hidden HTML form to /ibt/purge-cache. The browser dutifully attached our session cookie, the origin saw a

Read Full Tutorial open_in_new
arrow_back Back to Tutorials