Cross-Site Request Forgery Mitigation for Express.js Apps Made Easy Using The Same-Site Cookie Flag
Good post, appreciate the example. Where can I see the current browser support for “Same-Origin Policy”? does not show anything…

