Security· Oct 14, 2024 CSRF: When You Still Need to Care SameSite cookies made CSRF less of a default threat, but the attack is far from dead for APIs using cookie auth, subdomains, or older browsers. 3 min read Read →