#
DIFF.BLOG
New
Following
Discover
Jobs
More
Top Writers
Suggest a blog
Upvotes plugin
Report bug
Contact
About
Privacy
Sign up
The home for great developer writing.
We surface the best developer writing from thousands of independent blogs, updated daily.
Join Diff.blog
TOPICS
Cross-Site Request Forgery
·
Filippo Valsorda
·
Aug. 13, 2025, 5 p.m.
software development
web-security
Browser security
Cross-Site Request Forgery
Summary
The blog post discusses how modern browsers provide request metadata that can simplify the implementation of countermeasures against Cross-Site Request Forgery (CSRF) attacks.
Read full post on words.filippo.io →
MORE POSTS LIKE THIS
Automatic CSRF protection based on Fetch Metadata headers
andrewlock ·
Aug 4, 2026
software development
ASP.NET Core
External Authentication Policy in NGINX Ingress Controller: A Real World Use Case
Blog Nginx ·
Jun 22, 2026
ingress
knowledge-base
github: Sunsetting SHA-1 in HTTPS on GitHub
Sujith Quintelier ·
Apr 20, 2026
github
HTTPS
Deser: Rethinking Rust Serialization
Armin Ronacher ·
Sep 29, 2026
programming
software development
What TLA+ can and can't check
Hillel Wayne ·
Sep 30, 2026
programming
software development
Dear Software Makers
Jim Nielsen ·
Sep 30, 2026
Creativity
software development
Discover more posts →
AUTHOR
Advertise
Sponsor diff.blog
Put your product in front of developers who read and write about their craft. One exclusive sponsor at a time.
Become a sponsor →
BLOG POST FEATURED ON
Hacker News
151 points
Add this plugin to your blog
RECENT POSTS FROM THE AUTHOR
Choose how you want to continue.
Continue with GitHub
Continue with Google
By continuing, you agree to our
Privacy Policy
.