dvMiddlewareKeysAlwaysOn top-level constant
Keys the route already enforces for every request.
CSRF is validated in the generated request prelude on every method that changes state, before the handler and before this chain. Declaring the key is redundant, not wrong, so the build accepts it and emits nothing -- and this set is why, rather than a silent gap that looks identical.
Implementation
const Set<String> dvMiddlewareKeysAlwaysOn = <String>{'csrf'};