CSRF protection using HMAC-signed state tokens (RFC 5869, RFC 2104)
new