How does one protect against XSRF attacks in Grails. I see that forms support the notion of useToken which (I think should suffice). However, remoteForm or other AJAX related request don't support this feature.

Also, is there a way to invert the functionality of useToken so that it is always used rather than enabled on a case by case basis?

Edit
Report