SameSite cookies reduce some cross-site request risks
Marking a cookie SameSite stops the browser attaching it to requests originating from other sites.
That removes the mechanism cross-site request forgery depends on, which is why modern browser defaults have made a large class of that attack much harder. It is a useful default and not complete coverage, particularly where requests come from the same site by a route you did not intend.
More on Browser security
- Same-origin policy limits which pages can read each otherSame room, different desks
- CORS relaxes browser reading rules, not authenticationA propped hatch, not a checkpoint
- Browser extensions inherit powerful visibilityEverything passes under it
- Local storage is convenient, not a secure vaultOpen shelves by the door
- Content Security Policy constrains script sourcesOnly from the addresses you wrote down
- Clickjacking hides the real control beneath the clickPressed here. Answered there
