#
DIFF.BLOG
New
Following
Discover
Jobs
More
Top Writers
Suggest a blog
Upvotes plugin
Report bug
Contact
About
Sign up
The home for great developer writing.
We surface the best developer writing from thousands of independent blogs, updated daily.
Join Diff.blog
TOPICS
CSRF Protection without Tokens or Hidden Form Fields
266
·
Miguel Grinberg
·
Dec. 21, 2025, 4:09 p.m.
web-security
CSRF-Protection
development techniques
Microdot framework
Summary
A developer shares a novel approach to implementing CSRF protection in a web framework without traditional measures like tokens or hidden fields, offering a simpler solution to a common security issue.
Read full post on blog.miguelgrinberg.com →
MORE POSTS LIKE THIS
Automatic CSRF protection based on Fetch Metadata headers
andrewlock ·
Aug 4, 2026
software development
ASP.NET Core
Cloudflare Workers AI: run LLMs without API keys
Flaviocopes ·
Aug 15, 2026
APIs
development techniques
Device Bound Session Credentials lands in Chrome on macOS
ScottHelme ·
Aug 11, 2026
DBSC
macos
Looking At Tarpit and LLM Maze Stats
Bentasker Co ·
Aug 9, 2026
AI
Analysis
TIL: Unminimizing Ubuntu Docker images
Heitor ·
Aug 10, 2026
OCI
Ubuntu
CSRF from Scratch: Browser Mechanics, Attacks, and Spring Security Implementation [Full Handbook]
freeCodeCamp.org ·
Aug 7, 2026
Security
CSRF
Discover more posts →
AUTHOR
BLOG POST FEATURED ON
Hacker News
18 points
Add this plugin to your blog
RECENT POSTS FROM THE AUTHOR
Choose how you want to continue.
Continue with GitHub
Continue with Google