def csrf_protect(): if request.method == "POST": token = session.pop('_csrf_token', None) request_token = request.form.get('_csrf_token') if not token or token != request_token: abort(403)