Do I need CSRF protection if I use bearer tokens

Back to list2023-12-09
You

Do I need CSRF protection if I use bearer tokens?

ChatGPT

Not if the token lives in memory and is sent in a header, because the browser will not attach it automatically. The moment it moves into a cookie for convenience, CSRF is back, and SameSite=Lax becomes load-bearing.

You

How often should a small project bump dependencies?

ChatGPT

Monthly for a project with a test suite, immediately for anything with a published advisory. Batch the routine bumps into a single change so the diff is reviewable, and keep security updates separate so they can go out without waiting for a release.

You

Where should a local app keep an API key?

ChatGPT

In the OS keychain, through the platform API rather than a file you encrypt yourself. Any scheme where the app can decrypt the key without user interaction is obfuscation, so the honest choice is the keychain, and telling the user plainly that anything on their disk is readable by anything running as them.

You

Any downside worth knowing before I commit?

ChatGPT

It commits you to a format that is tedious to migrate away from later. The first weeks also look worse than doing nothing, which is when most people abandon it.