#
DIFF.BLOG
New
Following
Discover
Jobs
More
Top Writers
Suggest a blog
Upvotes plugin
Report bug
Contact
About
Sign up
The home for great developer writing.
We surface the best developer writing from thousands of independent blogs, updated daily.
Join Diff.blog
TOPICS
Automatic CSRF protection based on Fetch Metadata headers
13
·
·
Aug. 4, 2026, 10:37 a.m.
software development
ASP.NET Core
web-security
CSRF-Protection
Summary
This blog post discusses the new Cross-Site Request Forgery (CSRF) protection feature in ASP.NET Core that leverages Fetch Metadata HTTP headers as an alternative to traditional antiforgery tokens, detailing its implementation and benefits.
Read full post on andrewlock.net →
MORE POSTS LIKE THIS
dotnet: .NET 11 Preview 7 is now available!
Sujith Quintelier ·
Aug 12, 2026
C++
microsoft
Understanding the Fetch Metadata HTTP headers: Sec-Fetch-Site and friends
andrewlock ·
Jul 29, 2026
Web Development
HTTP Headers
External Authentication Policy in NGINX Ingress Controller: A Real World Use Case
Blog Nginx ·
Jun 22, 2026
ingress
knowledge-base
Hangfire as an MCP Operations Pane for AI Agents
Nikiforov Alexey ·
May 2, 2026
authentication
software development
CSRF Protection without Tokens or Hidden Form Fields
Miguel Grinberg ·
Dec 21, 2025
web-security
CSRF-Protection
.NET 10 is now available for RHEL and OpenShift
Red Hat ·
Nov 17, 2025
Cryptography
RHEL
Discover more posts →
AUTHOR
RECENT POSTS FROM THE AUTHOR
Choose how you want to continue.
Continue with GitHub
Continue with Google