MC Stuff wrote... Hi Chandran, CSRF token filter will trigger only for authenticated requests and for anonymous it will never be called. Hence empty string for anonymous is not a valid case. Thanks, Thanks MC,this means in publish environment if end users accessing the page CSRF token will ...