From csrf-protection
Implements CSRF protection using synchronizer tokens, double-submit cookies, and SameSite attributes for Express and Flask apps.
How this skill is triggered — by the user, by Claude, or both
Slash command
/csrf-protection:csrf-protectionThe summary Claude sees in its skill listing — used to decide when to auto-load this skill
Defend against Cross-Site Request Forgery attacks using multiple protection layers.
Defend against Cross-Site Request Forgery attacks using multiple protection layers.
| Method | How It Works | Browser Support |
|---|---|---|
| Synchronizer Token | Hidden form field validated server-side | All |
| Double Submit | Cookie + header must match | All |
| SameSite Cookie | Browser blocks cross-origin requests | Modern |
const crypto = require('crypto');
function generateToken() {
return crypto.randomBytes(32).toString('hex');
}
// Middleware
app.use((req, res, next) => {
if (!req.session.csrfToken) {
req.session.csrfToken = generateToken();
}
res.locals.csrfToken = req.session.csrfToken;
next();
});
// Validation
app.post('*', (req, res, next) => {
const token = req.body._csrf || req.headers['x-csrf-token'];
// crypto.timingSafeEqual throws RangeError when buffers differ in length,
// so check length explicitly first (still constant-time on the equal-length path).
const csrf = req.session.csrfToken || '';
if (!token || token.length !== csrf.length) {
return res.status(403).json({ error: 'Invalid CSRF token' });
}
if (!crypto.timingSafeEqual(Buffer.from(token), Buffer.from(csrf))) {
return res.status(403).json({ error: 'Invalid CSRF token' });
}
next();
});
app.use(session({
cookie: {
httpOnly: true,
secure: true,
sameSite: 'strict', // or 'lax'
maxAge: 3600000
}
}));
<form method="POST" action="/transfer">
<input type="hidden" name="_csrf" value="<%= csrfToken %>">
<button type="submit">Submit</button>
</form>
See references/python-react.md for:
npx claudepluginhub secondsky/claude-skills --plugin csrf-protectionImplements CSRF protection using synchronizer tokens, double-submit cookies, SameSite attributes, and origin validation. Useful for securing forms and state-changing operations.
Prevents CSRF attacks by validating request origin and using unpredictable tokens for state-changing operations. Covers SameSite cookies, sync token pattern, double-submit cookie pattern, and origin header validation.
Protects state-changing endpoints (POST, PUT, PATCH, DELETE) from cross-site request forgery using synchronizer tokens, SameSite cookies, or origin verification.