<?xml version="1.0" encoding="UTF-8"?><oembed><type>video</type><version>1.0</version><html>&lt;iframe src=&quot;https://www.loom.com/embed/535bb21e27c246d2be09122d5b6823ff&quot; frameborder=&quot;0&quot; width=&quot;1920&quot; height=&quot;1440&quot; webkitallowfullscreen mozallowfullscreen allowfullscreen&gt;&lt;/iframe&gt;</html><height>1440</height><width>1920</width><provider_name>Loom</provider_name><provider_url>https://www.loom.com</provider_url><thumbnail_height>1440</thumbnail_height><thumbnail_width>1920</thumbnail_width><thumbnail_url>https://cdn.loom.com/sessions/thumbnails/535bb21e27c246d2be09122d5b6823ff-00001.gif</thumbnail_url><duration>239.20940999999965</duration><title>Understanding CSRF Tokens</title><description>In this video, I provide more context on CSRF tokens and explain why we have not implemented them in Memberstack. CSRF tokens are used to ensure that the person filling out a form is the original person with the intent. Implementing CSRF tokens is easy if you have first-party access to the website&apos;s domain, which Memberstack did not have until recently. I discuss the requirements for implementing secure CSRF tokens and mention a new feature in Memberstack that allows us to properly implement them. No action is requested from the viewers.</description></oembed>