๐—ฆ๐˜๐—ผ๐—ฝ ๐—–๐—ฆ๐—ฅ๐—™ ๐—”๐˜๐˜๐—ฎ๐—ฐ๐—ธ๐˜€ ๐—œ๐—ป ๐—ฌ๐—ผ๐˜‚๐—ฟ ๐—ฃ๐—›๐—ฃ ๐—”๐—ฑ๐—บ๐—ถ๐—ป ๐—ฃ๐—ฎ๐—ป๐—ฒ๐—น

A researcher hacked my admin panel. He used a fake form. I was logged in. He published a video without my knowledge. This is CSRF.

Session tokens often break with page caching. They also break when you open multiple tabs. Double-submit cookies solve this.

The process is simple.

Attackers are unable to read your cookies. They fail to match the value. The request fails.

Follow these rules for your code:

Follow these operational rules:

Secure your admin panel before someone else does.

Source: https://dev.to/ahmet_gedik778845/implementing-csrf-double-submit-cookies-in-a-php-video-admin-panel-2c60