If you’re thinking of upgrading to MVC 2.0, and you take advantage of the AntiForgeryToken support then be careful – you can easily kick out all active visitors after the upgrade until they restart their browser. Why’s this? For the anti forgery validation to take place, ASP.NET MVC uses a session cookie called “__RequestVerificationToken_Lw__”.
This gets checked for and de-serialized … Read more “Beware: Upgrade to ASP.NET MVC 2.0 with care if you use AntiForgeryToken”