I'm looking into github.com/gorilla/csrf to figure out if we could bring CSRF protection to the standard library.

I am 90% sure the secret key is useless: it signs a random token with no metadata, and the attacker can just get and reuse a valid signed token.

Am I missing something?

0

If you have a fediverse account, you can quote this note from your own instance. Search https://abyssdomain.expert/users/filippo/statuses/114352739289499419 on your instance and quote it. (Note that quoting is not supported in Mastodon.)