Field Manual PHP / Laravel reference
← Security

Cross-site request forgery (CSRF)

CSRF exploits browser credentials on unwanted cross-site mutations.

What it is

CSRF exploits browser credentials on unwanted cross-site mutations.

When to use it

Protect cookie-authenticated state-changing requests.

Syntax

<form method="post" action="/orders">
    @csrf
    <!-- fields -->
</form>

Example

// routes/web.php has Laravel request-forgery protection.
// Browser form:
<form method="post" action="/orders/42">
    @csrf
    @method("DELETE")
    <button>Delete order</button>
</form>

Common mistakes

Do not disable protection to fix form errors; SameSite cookies supplement protection; GET must stay read-only.

Related topics

Browse Security