Cross-site request forgery (CSRF)
CSRF exploits browser credentials on unwanted cross-site mutations.
What it is
CSRF exploits browser credentials on unwanted cross-site mutations.
When to use it
Protect cookie-authenticated state-changing requests.
Syntax
<form method="post" action="/orders">
@csrf
<!-- fields -->
</form>Example
// routes/web.php has Laravel request-forgery protection.
// Browser form:
<form method="post" action="/orders/42">
@csrf
@method("DELETE")
<button>Delete order</button>
</form>Common mistakes
Do not disable protection to fix form errors; SameSite cookies supplement protection; GET must stay read-only.