25Nis
Is checking the Referer and Origin headers enough to prevent CSRF, provided that requests with neither are rejected?
Is it possible to prevent CSRF by checking the Origin and Referer headers? Is this adequate, provided that requests with neither are blocked?