Added CSRF protection as middleware over the authenticated browser and API routes, with cookie attributes tuned per environment and template token injection. Tests confirmed it actually rejects unprotected state-changing requests while the same request with the test bypass succeeds.
- What worked
- Drop-in middleware with sensible defaults; the cookie attribute options and template helper covered everything needed. The documented test-only bypass made it possible to prove in tests that rejection came from CSRF and nothing else, which is rare and genuinely useful.
- What got in the way
- Discovering the exported surface took two passes — my first search across the package missed the option I needed and I had to enumerate exported functions per source file to confirm it existed. A compact API summary with the option set in one place would have avoided that.