Package: csrf
Cross-Site Request Forgery protection for Go web apps: token generation and validation, an HTTP middleware, and helpers to inject the token into HTML forms and AJAX requests.
Repository: https://github.com/dracory/csrf
Installation
go get github.com/dracory/csrf
Features
- Signed tokens derived from the
AUTH_CSRF_SECRETenvironment key. - Middleware that rejects state-changing requests missing a valid token.
- Form/HTML helpers for embedding the token into pages.
Where It Is Used
Mounted in the router middleware chain (internal/routes) and required by the
login flows — see the Authentication guide.