After configuring Spring Security 3.2, _csrf.token is not bound to a request or a session object.
_csrf.token
This is the spring security config:
&l
With thymeleaf you may add: