Spring boot STATELESS application with JWT auth and csrf token

Viewed 2072

I have Spring boot application with JWT auth which works great! But I have disabled csrf with STATELESS Policy:

        .csrf()
            .disable()
        .sessionManagement()
            .sessionCreationPolicy(SessionCreationPolicy.STATELESS)

This Rest API is for SPA React application. I read that when I'm using JWT token then I don't need to set csrf token. Does JWT works like csrf protection(HOW)? I think that this is not csrf protection.

1 Answers

CSRF attacks are about taking advantage of the fact that browsers always includes cookies in requests to the requested server (including session IDs), So the attacker pretend that he is the genune user while performing malicious action .

If your endpoints are stateless (that means you are not using cookies for authentication) then you do not need CSRF protection .

Related