I was referring in particular to new guidance which came out of the Go community recently. I came across this article maybe a month ago at random, but I’ve been seeing it pop up more and more. I’d imagine within a year most will be aware of it.
Your quote is missing the “library” part, which substantially changes the meaning. Of course we must still protect against CSRF, but the method Plug uses is (as of fairly recently) outdated.






















