#
DIFF.BLOG
New
Following
Discover
Jobs
More
Top Writers
Suggest a blog
Upvotes plugin
Report bug
Contact
About
Sign up
The home for great developer writing.
We surface the best developer writing from thousands of independent blogs, updated daily.
Join Diff.blog
TOPICS
Automatic CSRF protection based on Fetch Metadata headers
·
·
Aug. 4, 2026, 10:37 a.m.
CSRF-Protection
ASP.NET Core
Fetch Metadata
web-security
Summary
This blog post discusses the new Cross-Site Request Forgery (CSRF) protection feature in ASP.NET Core that leverages Fetch Metadata HTTP headers as an alternative to traditional antiforgery tokens, detailing its implementation and benefits.
Read full post on andrewlock.net →
MORE POSTS LIKE THIS
(WITH-AI ...)
Funcall Blogspot ·
Aug 23, 2026
ai-coding
Vibe Coding
dotnet: .NET 11 Preview 7 is now available!
Sujith Quintelier ·
Aug 12, 2026
.NET
microsoft
Understanding the Fetch Metadata HTTP headers: Sec-Fetch-Site and friends
andrewlock ·
Jul 29, 2026
HTTP Headers
Fetch Metadata
External Authentication Policy in NGINX Ingress Controller: A Real World Use Case
Blog Nginx ·
Jun 22, 2026
ingress
Kubernetes
Hangfire as an MCP Operations Pane for AI Agents
Nikiforov Alexey ·
May 2, 2026
hangfire
ASP.NET Core
CSRF Protection without Tokens or Hidden Form Fields
Miguel Grinberg ·
Dec 21, 2025
CSRF-Protection
web-security
Discover more posts →
AUTHOR
Sponsored
Zulip
Organized team chat for people who take work seriously. Topic-based threading keeps conversations focused.
Try Zulip
Become a sponsor →
RECENT POSTS FROM THE AUTHOR
Choose how you want to continue.
Continue with GitHub
Continue with Google