<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>CSRF on 安橙的博客</title><link>https://blog.ans20xx.com/tags/csrf/</link><description>Recent content in CSRF on 安橙的博客</description><generator>Hugo -- 0.161.1</generator><language>zh</language><lastBuildDate>Sat, 23 May 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://blog.ans20xx.com/tags/csrf/index.xml" rel="self" type="application/rss+xml"/><item><title>Day 04 · 会话管理与 Web 安全 · Session / CSRF / XSS</title><link>https://blog.ans20xx.com/posts/backend/authn-authz-day04/</link><pubDate>Sat, 23 May 2026 00:00:00 +0000</pubDate><guid>https://blog.ans20xx.com/posts/backend/authn-authz-day04/</guid><description>认证授权 30 天 Day 04：理解 Session 完整生命周期与 Session Fixation 攻击，对比 CSRF 的四种防御方案，区分 Stored/Reflected/DOM 三种 XSS，并用 Go 实现安全的 Cookie / CSRF Token / CSP 中间件。</description></item></channel></rss>