CSRF Protection — Complete Guide
CSRF Protection — Complete Guide: free step-by-step lesson with examples, common mistakes, and interview tips — part of MEAN Stack Tutorial on Toolliyo Academy.
On this page
MEAN Stack Tutorial · Lesson 57 of 100
CSRF Protection
Stack ✓ → Projects
Projects · 2 — Apps · ~10 min · MEAN — Authentication & Security
What is this?
CSRF protection stops malicious sites from triggering authenticated requests to MeanVerse API using victim's browser cookies.
Why should you care?
If refresh token or session cookie auto-sends, forged POST can transfer funds.
See it live — copy this example
Paste into your MeanVerse project (Angular + Express + MongoDB), then run with ng serve / node / mongosh as noted.
import csrf from 'csurf';
const csrfProtection = csrf({ cookie: { httpOnly: true, sameSite: 'strict' } });
router.get('/auth/csrf', csrfProtection, (req, res) => {
res.json({ csrfToken: req.csrfToken() });
});
router.post('/transfers', csrfProtection, auth, createTransfer);
// Angular loads token then sends header
this.http.post('/api/transfers', body, {
headers: { 'X-CSRF-Token': this.csrfToken }
});
What happened?
- Server sets CSRF secret cookie.
- Client fetches token and sends custom header — cross-origin forms cannot read token due to same-origin policy.
Practice next
- Enable csurf on cookie-authenticated routes.
- Angular service fetches CSRF on app init.
- Use SameSite=Strict on auth cookies.
- Switch sensitive ops to Authorization header only.
- Verify CSRF fails without X-CSRF-Token in Postman test.
Remember
CSRF targets cookie-based auth. Double-submit cookie or synchronizer token pattern. SameSite cookies add modern browser layer.
Cookie session legacy
Older MeanVerse module uses session cookies for admin.
Outcome: CSRF tokens added; forged transfer POST blocked.
Interview prep for this lesson
Practice these questions aloud after reading—each links to a full structured answer.
Sign in to ask a question or upvote helpful answers.
No questions yet — be the first to ask!