Expand description
CSRF protection via double-submit cookie.
Verifies state-changing POSTs with a double-submit __Host- cookie compared in constant time.
Constants§
- COOKIE_
NAME - Names the
__Host--prefixed CSRF cookie. - FIELD_
NAME
Functions§
- current_
token - Reads the current token without setting one, safe inside streamed children.
- ensure_
token - Ensures a request token before headers send, returning
""without a cookie layer. - field
- Renders the hidden field embedding the given token.
- verify
- Verifies the submitted token matches the cookie with a constant-time compare, failing closed with 403.