Amon2::Plugin::Web::CSRFDefender - Anti CSRF filter
package MyApp::Web; use Amon2::Web; __PACKAGE__->load_plugin('Web::CSRFDefender');
This plugin denies CSRF request.
Get a CSRF defender token. This method is useful to add token for AJAX request.
You can validate CSRF token manually.
Do not run validation automatically.
Disable HTML rewriting filter. By default, CSRFDefender inserts XSRF token for each form element.
It's very useful but it hits performance issue if your site is very high traffic.
You can change the csrf token generation algorithm.
Copyright (C) Tokuhiro Matsuno.
This library is free software; you can redistribute it and/or modify it under the same terms as Perl itself.
Tokuhiro Matsuno <firstname.lastname@example.org>
Kazuho Oku and mala for security advice.