In February, AntiForgeryToken was only migrated from “MVC Futures” to “MVC Core”, so the likelihood that the synchronization was not done by the embedded device did not allow this.
Another possible reason is that the team that developed the MVC framework really put all the power into the hands of the developers. You can use something else instead of AntiForgeryToken in the same way as you can use a different testing structure, data structure, etc. This is a new approach when you look at MS historically, where they will use you in using what they put.
source share