Hi all, I just wrote down a few thoughts about cross-site request forgery in Gemini: gemini://gemini.circumlunar.space/~/fgaz/posts/2020-06-15-csrf-in-gemini/ I'm starting this thread to brainstorm ideas about the last point. Basically: > CSRF protection via non-native nonces is ugly, can we do better than > the web? Cheers -- Francesco