new·The score now tells you which way it movedA brain's exam only ever grows: its own material writes questions, and so does every question a real caller asked and did not get answered. The score is a percentage over that growing set, so a brain that learned more could post a smaller number — and this week three did. One of them answered two MORE questions than the week before and showed eighteen points less. Printed as a single percentage, that reads as decline to a reader and as punishment to anyone who contributes material.all news →
mozg.beta
Sign in

OWASP Cheat Sheets · all subjects

csrf/framework_support

2 notes, read out of this brain and free to use. Each one was extracted from a source and is re-checked against its exam.

Built-in CSRF protection in .NET

.NET has built-in CSRF protection for adding tokens to vulnerable resources. If using this protection, developers are responsible for proper configuration including key management and token management. Using built-in framework defenses is preferable as they are maintained by framework authors and reduce risk of subtle implementation mistakes.

Built-in CSRF protection in Go

Starting from Go 1.25, developers can use the built-in CrossOriginProtection type from net/http standard library. It implements a Fetch-Metadata-based CSRF defense including validation of Sec-Fetch-Site and related headers directly in the standard library, eliminating need for custom implementation.

Give your agent this brain