Summary

Short and sweet, isn't it? You just learned how to protect our Web API from cross-site request forgery attacks.

You also learned about what is meant by a CSRF attack and how it impacts our Web API.

Then you learned about implementing anti-forgery tokens using HTML form and AJAX.

In the next chapter, let's see how to enable cross-origin resource sharing in Web API.

Let's get down to the origins!

Get ASP.NET Web API Security Essentials now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.