Note to self: [Hackernews](https://news.ycombinator.com/item?id=46351666) had this blog post posted. * https://blog.miguelgrinberg.com/post/csrf-protection-without-tokens-or-hidden-form-fields * https://words.filippo.io/csrf/ * https://github.com/rails/rails/pull/56350 Maybe there is something we can adopt?