#
DIFF.BLOG
New
Following
Discover
Jobs
More
Top Writers
Suggest a blog
Upvotes plugin
Report bug
Contact
About
Sign up
The home for great developer writing.
We surface the best developer writing from thousands of independent blogs, updated daily.
Join Diff.blog
TOPICS
Cross-Site Request Forgery
·
Filippo Valsorda
·
Aug. 13, 2025, 5 p.m.
Cross-Site Request Forgery
web-security
Browser security
software development
Summary
The blog post discusses how modern browsers provide request metadata that can simplify the implementation of countermeasures against Cross-Site Request Forgery (CSRF) attacks.
Read full post on words.filippo.io →
MORE POSTS LIKE THIS
Automatic CSRF protection based on Fetch Metadata headers
andrewlock ·
Aug 4, 2026
CSRF-Protection
ASP.NET Core
External Authentication Policy in NGINX Ingress Controller: A Real World Use Case
Blog Nginx ·
Jun 22, 2026
ingress
Kubernetes
github: Sunsetting SHA-1 in HTTPS on GitHub
Sujith Quintelier ·
Apr 20, 2026
sha-1
HTTPS
Debian Code Search: Fast TurboPFor with Go SIMD
stapelberg ·
Sep 6, 2026
Go Programming
SIMD
Hardening Container Images
Grepular ·
Sep 5, 2026
Security
sysadmin
s/Neovim/Helix/g
mrusme ·
Sep 6, 2026
neovim
Helix
Discover more posts →
AUTHOR
Sponsored
Zulip
Organized team chat for people who take work seriously. Topic-based threading keeps conversations focused.
Try Zulip
Become a sponsor →
BLOG POST FEATURED ON
Hacker News
151 points
Add this plugin to your blog
RECENT POSTS FROM THE AUTHOR
Choose how you want to continue.
Continue with GitHub
Continue with Google