I still can't seem to get good informantion if this should be common usage on something like React SPAs for things like signup forms and other forms publicly POSTing data?
However I’m not so sure about this, as I still implement CSRF tokens in my SPAs. (Bit of a habit from my php days) I store the tokens in local storage and pass them through the request headers.
A lot of people have different ideas and methods when it comes to CSRF protection on SPAs. I’d love to hear other people’s opinion and tactics!
Feel free to correct me on anything.
Article: https://medium.com/tresorit-engineering/modern-csrf-mitigati...