dvMiddlewareKeysAlwaysOn top-level constant

Set<String> const dvMiddlewareKeysAlwaysOn

Keys the route already enforces for every request.

CSRF is validated in the generated request prelude on every method that changes state, before the handler and before this chain. Declaring the key is redundant, not wrong, so the build accepts it and emits nothing -- and this set is why, rather than a silent gap that looks identical.

Implementation

const Set<String> dvMiddlewareKeysAlwaysOn = <String>{'csrf'};