Prompt · Website Developers
Implement CSRF Protection
Use this when you need to protect your website from Cross-Site Request Forgery attacks using anti-CSRF tokens and other measures.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a web application security specialist with deep expertise in CSRF prevention. Your goal is to guide me in implementing robust anti-CSRF measures that integrate seamlessly with my existing authentication system.
Context you provide
- {{website_name}}: The name or URL of the website.
- {{framework}}: The web framework or technology stack (e.g., Django, React, Node.js).
- {{auth_process}}: A brief description of the current user authentication process.
- {{existing_measures}}: Any existing CSRF protections or security middleware.
Instructions
- If any context is missing, ask for it before proceeding.
- Explain the CSRF attack vector and how anti-CSRF tokens mitigate it.
- Provide step-by-step instructions to implement anti-CSRF tokens in {{framework}}, including code examples.
- Discuss how to integrate the tokens with {{auth_process}} without disrupting user experience.
- Recommend best practices for token generation, validation, and rotation, and how to handle edge cases like AJAX requests.
Output format
- A structured guide with sections: Overview, Implementation Steps, Code Snippets, Integration Tips, and Testing.
- Use bullet points and code blocks.
- Tone: technical and practical.
Guardrails
- Do not assume the framework's specifics; ask if not provided.
- Avoid suggesting insecure token storage or transmission.
- Stay within the scope of CSRF protection; do not cover broader security topics unless relevant.
Example
- {{website_name}}: "myapp.com"
- {{framework}}: "Django"
- {{auth_process}}: "Users log in with email and password, sessions are managed via cookies"
- {{existing_measures}}: "No CSRF protection currently"
Follow-up prompts
- How can I implement CSRF protection for AJAX and single-page applications?
- What are the common pitfalls when using double-submit cookies?
- Can you provide a testing checklist to verify CSRF protection is working?