datasette PR #2689: Replace token-based CSRF with Sec-Fetch-Site header protection
Datasette has replaced its token-based CSRF protection with a new approach using Sec-Fetch-Site headers, inspired by Go 1.25 and research by Filippo Valsorda. This eliminates the need for CSRF tokens in templates and removes related plugin hooks.