Description
In ASP.NET Core, IgnoreAntiforgeryToken disables antiforgery validation for the controller or action. On state-changing requests that use cookie-based authentication, this can let attackers make a user's browser perform unwanted actions.
Potential impact
- Automatically sent authentication cookies may authorize account changes, payments, or data deletion.
- Applying this setting to administrative functions can allow misuse of a privileged user's session.
Remediation
Remove IgnoreAntiforgeryToken from state-changing actions and validate antiforgery tokens. For API-only endpoints, review authentication methods that browsers do not send automatically, along with the CORS policy.
Examples
Before
csharp
[IgnoreAntiforgeryToken]
[HttpPost("transfer")]
public IActionResult Transfer()
{
return Ok();
}
After
csharp
[ValidateAntiForgeryToken]
[HttpPost("transfer")]
public IActionResult Transfer()
{
return Ok();
}
Explanation:
- Before: Explicitly disabling antiforgery validation on a state-changing ASP.NET Core endpoint can enable CSRF when authentication uses cookies.
- After: Remove
IgnoreAntiforgeryTokenand require antiforgery tokens for state changes, or use an authentication mechanism that browsers do not send automatically.