#
DIFF.BLOG
New
Following
Discover
Jobs
More
Top Writers
Suggest a blog
Upvotes plugin
Report bug
Contact
About
Sign up
The home for great developer writing.
We surface the best developer writing from thousands of independent blogs, updated daily.
Join Diff.blog
TOPICS
CSRF Protection without Tokens or Hidden Form Fields
·
Miguel Grinberg
·
Dec. 21, 2025, 4:09 p.m.
CSRF-Protection
web-security
Microdot framework
development techniques
Summary
A developer shares a novel approach to implementing CSRF protection in a web framework without traditional measures like tokens or hidden fields, offering a simpler solution to a common security issue.
Read full post on blog.miguelgrinberg.com →
MORE POSTS LIKE THIS
Deconstructing the Architecture of AI-Orchestrated Web Attacks
Linode ·
Aug 25, 2026
AI
web-security
(WITH-AI ...)
Funcall Blogspot ·
Aug 23, 2026
ai-coding
Vibe Coding
Automatic CSRF protection based on Fetch Metadata headers
andrewlock ·
Aug 4, 2026
CSRF-Protection
ASP.NET Core
Responsive text and code
Unsung ·
Sep 5, 2026
responsive design
mobile usability
Speeding up Elixir test suites
Zarar Siddiqi ·
Sep 2, 2026
elixir
Testing
Trusting a self-signed localhost certificate in Chrome on Linux
Daniel Opitz ·
Sep 2, 2026
self-signed certificates
Chrome
Discover more posts →
AUTHOR
Sponsored
Zulip
Organized team chat for people who take work seriously. Topic-based threading keeps conversations focused.
Try Zulip
Become a sponsor →
BLOG POST FEATURED ON
Hacker News
18 points
Add this plugin to your blog
RECENT POSTS FROM THE AUTHOR
Choose how you want to continue.
Continue with GitHub
Continue with Google