- CsrfProtectionSubscriber: auto-injects hidden _csrf_token in HTML responses, auto-verifies on POST requests - Excludes: webhooks, JSON APIs, login (has its own CSRF) - 9 tests covering all cases (GET, excluded, JSON, no token, invalid, valid, inject, non-HTML) Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>