The following talk https://youtu.be/67mezK3NzpU?t=2408 at 40:08min, Hubert mentions that the best way to prevent a CSRF attack is to do the following:
- Generate a random id server side - lets call this the CSRF id.
- Add this id to your jwt cookie. Also add a response header with the id (e.g. csrfId: xxx)
- Have the client save the id to local storage.
- On each request, the client should append a header with this id.
- On each request, the server should verify that the id in the received cookie matches the one in the received header.
My question is: what would stop the CSRF attacker reading the cookie manually, getting the ID and then adding that to the attack request?
Also, wont localstorage leave the ID vulnerable to a XSS + CSRF combination attack? (I'm not sure this is possible)?