Protect non-idempotent requests with anti-CSRF tokens or SameSite cookies plus origin verification.
Why This Matters
Without CSRF defenses, attackers can trigger authenticated state changes from a victim's browser (OWASP A01).
Related Rules
Catch this automatically on every PR
BeforeMerge scans your pull requests against this rule and dozens more. Get actionable feedback before code ships.