Config files : Cross-site request forgery (CSRF)