Cross-Site Request Forgery, Explained: From a Hidden Form to an Account Takeover
A signed-in browser attaches its session cookie to requests that another site starts. Here is how cross-site request forgery turns that into actions the user never chose, why SameSite cookies alone do not settle it, and how tokens and origin checks close the gap.