Disabled CSRF protection

Disabled CSRF protection in C#

Description

In ASP.NET Core, IgnoreAntiforgeryToken disables antiforgery validation for the controller or action. On state-changing requests that use cookie-based authentication, this can let attackers make a user's browser perform unwanted actions.

Potential impact

  • Automatically sent authentication cookies may authorize account changes, payments, or data deletion.
  • Applying this setting to administrative functions can allow misuse of a privileged user's session.

Remediation

Remove IgnoreAntiforgeryToken from state-changing actions and validate antiforgery tokens. For API-only endpoints, review authentication methods that browsers do not send automatically, along with the CORS policy.

Examples

Before

csharp
[IgnoreAntiforgeryToken]
[HttpPost("transfer")]
public IActionResult Transfer()
{
    return Ok();
}

After

csharp
[ValidateAntiForgeryToken]
[HttpPost("transfer")]
public IActionResult Transfer()
{
    return Ok();
}

Explanation:

  • Before: Explicitly disabling antiforgery validation on a state-changing ASP.NET Core endpoint can enable CSRF when authentication uses cookies.
  • After: Remove IgnoreAntiforgeryToken and require antiforgery tokens for state changes, or use an authentication mechanism that browsers do not send automatically.

References