Since we already had a post on the topic, I went with updating it rather than creating a new one, and this might be worth checking if you're interested in security:
http://blog.orbeon.com/2013/11/preventing-cross-site-request-forgery.htmlEnjoy,
Alex
--
Follow Orbeon on Twitter: @orbeon
Follow me on Twitter: @avernet