What is the primary defense against Cross-Site Request Forgery (CSRF) attacks in web applications?
-
A
Input validation on all form fields
-
B
Synchronizer token pattern using unpredictable CSRF tokens
-
C
Enforcing HTTPS on all pages
-
D
Setting the HttpOnly flag on session cookies