/
<input type="hidden" name="csrf" value"djaskl;fhasdkjkfhasd"/>
lighttpd.conf.template
setenv.add-response-header += ("set-Cookie" => "X-XSRF-TOKEN=sdfasdfasdf; SameSite=Strict; Secure; HttpOnly; Path=/")