So we have a platform secured with a JWT access-token. To access platform REST API, we send the token in a Bearer Authorization header; when fetching static content (such as SPAs' code, CSS, fonts, or even for jumping between SPAs) we send the token in a Cookie since we have no control over those requests. We were OK so far...
At some point in time we added Spring Security in our APIs. This made some things easier for us but SonarQube displayed warnings for disabling Spring Security's CSRF protection (when configuring the framework we thougt pfff, we use headers to transport our JWT, we don't need CSRF protection for our APIs), but we tried to solve the warning anyway.
Investigating we came across SameSite attribute for Cookies and we are kind of confused if this would solve all of our problems.
So the question would be: is SameSite cookies' attribute enough for CRSF protection?
If so, is there a way to let Spring Security / SonarQube that we're OK against such attacks?