Forwarded headers CSRF hints

I want to link the other conversation on this to here as well. I’m in support of tweaking how csrf is handled to be more clear on what should be changed.

1 Like