CSRF Demo

Global Protection

The engine verifies every unsafe request before it calls the controller action.

Send the token as _token or X-CSRF-Token. Safe methods do not require it.

CSRF Token

Current CSRF Token: c0eeeae9e52af940a8b19eae4e2d9eacd5fc055a85ddd51e81cfbd7e0514c354

Form with CSRF Protection

Blocked Form

The engine rejects this request before submit() runs.