#
DIFF.BLOG
New
Following
Discover
Jobs
More
Top Writers
Suggest a blog
Upvotes plugin
Report bug
Contact
About
Sign up
The home for great developer writing.
We surface the best developer writing from thousands of independent blogs, updated daily.
Join Diff.blog
TOPICS
Cross-Site Request Forgery
111
·
Filippo Valsorda
·
Aug. 13, 2025, 5 p.m.
Cross-Site Request Forgery
web-security
Browser security
software development
Summary
The blog post discusses how modern browsers provide request metadata that can simplify the implementation of countermeasures against Cross-Site Request Forgery (CSRF) attacks.
Read full post on words.filippo.io →
MORE POSTS LIKE THIS
Automatic CSRF protection based on Fetch Metadata headers
andrewlock ·
Aug 4, 2026
CSRF-Protection
ASP.NET Core
External Authentication Policy in NGINX Ingress Controller: A Real World Use Case
Blog Nginx ·
Jun 22, 2026
ingress
knowledge-base
github: Sunsetting SHA-1 in HTTPS on GitHub
Sujith Quintelier ·
Apr 20, 2026
sha-1
HTTPS
You can just choose how many bugs you want now
nolanlawson ·
Aug 16, 2026
software-engineering
AI
★ Anthropic’s ‘Watermark’ Text Adulteration in Claude Is a Perversion of Writing
Daring Fireball ·
Aug 16, 2026
AI Ethics
text-generation
Nobody Knows Anything
Rohit Krishnan ·
Aug 16, 2026
ignorance
Personal Experience
Discover more posts →
AUTHOR
BLOG POST FEATURED ON
Hacker News
151 points
Add this plugin to your blog
RECENT POSTS FROM THE AUTHOR
Choose how you want to continue.
Continue with GitHub
Continue with Google