# Enable stateless CSRF protection for forms and logins/logouts framework: form: csrf_protection: token_id: submit csrf_protection: check_header: true stateless_token_ids: - submit - authenticate - logout