CSRF when the API is token based

Back to list2025-05-18
You

Do I need CSRF protection if I use bearer tokens?

ChatGPT

Not if the token lives in memory and is sent in a header, because the browser will not attach it automatically. The moment it moves into a cookie for convenience, CSRF is back, and SameSite=Lax becomes load-bearing.

You

How often should a small project bump dependencies?

ChatGPT

Monthly for a project with a test suite, immediately for anything with a published advisory. Batch the routine bumps into a single change so the diff is reviewable, and keep security updates separate so they can go out without waiting for a release.