.NET Core CSRF

代码:

//配置所有POST请求都加入 ValidateAntiforgeryToken 验证
            services.AddAntiforgery(options =>
            {
                options.FormFieldName = "AntiforgeryFieldName";
                options.HeaderName = "X-CSRF-TOKEN-HEADERNAME";
                options.SuppressXFrameOptionsHeader = false;
            });
            services.AddMvc(options =>
            {
                options.Filters.Add(new AutoValidateAntiforgeryTokenAttribute());
            });
原文地址:https://www.cnblogs.com/xsj1989/p/13847527.html