CSRF concerns requests carrying ambient browser credentials such as cookies. The defense depends on authentication transport and deployment behavior.
Before you start
You should know Java classes, dependency injection and basic HTTP requests. Identify where a call crosses a framework-managed boundary. The snippets illustrate a focused mechanism; database configuration, application wiring and authentication must be supplied by the surrounding application when applicable.
The practical goal is to reason through this situation: A cookie-authenticated mutation needs an appropriate CSRF strategy. Read the walkthrough first, then try the interview exercise before opening its answer. The important part is explaining the decision and its consequences, rather than remembering a definition alone.
Step-by-step walkthrough
Step 1: Inspect credential transport
Determine whether the browser automatically attaches authentication cookies.
Step 2: Model cross-site requests
JSON responses do not remove ambient-credential risks on mutations.
Step 3: Choose coordinated defenses
Evaluate CSRF strategy, cookie attributes, CORS and token handling together.
Worked scenario
A cookie-authenticated mutation needs an appropriate CSRF strategy.
A browser may send a session cookie on a request initiated from another site under applicable cookie rules. The server cannot infer user intent merely from that authenticated request. An API using an explicitly attached bearer token has a different transport model, but its token handling and origin policies still need deliberate design.
Common mistake
Disabling protection because an API returns JSON does not address how credentials are sent.
Verify the behavior
Test mutation requests with missing or invalid CSRF proof under the actual authentication transport.
Interview exercise
Evaluate a stateless API.
Answer and reasoning
Examine whether browsers automatically attach credentials, CORS policy and token handling before selecting CSRF configuration.
Continue learning
Compare the scenario with the Spring Boot interview questions and test your understanding with the Spring Boot MCQs. For terminology and implementation details, consult the reference material.