Collected research
That single GraphQL issue that you keep missing
GraphQL endpoints can remain CSRF-prone when middleware accepts form-encoded POST bodies, mutations are allowed over GET, or state-changing operations are exposed as queries. The article shows how these behaviors enable browser-driven mutations and XS-Search timing probes, then outlines framework, origin, cookie, and method-based defenses.
Record
- Researcher
- Tomasz Swiadek and Andrea Brancaleoni
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Tomasz Swiadek and Andrea Brancaleoni, first published at the original source. Preserved copies are kept so the citation survives its host.