CSRF
...
<div>
<form action="Transfer" method="post">
Amount: <input type="text" name="Amount" value="" /><br />
To Account: <input type="text" name="Account" value="" /><br />
<input type="submit" value="Transfer Money" />
@Html.AntiForgeryToken("someSecretKey1")
</div>
... class MoneyTransactionController: Controller
{
[ValidateAntiForgeryToken(salt="someSecretKey1")]
public ActionResult Transfer()
{
//business logic to handle money transfer
return View();
}
}Last updated