Hi
Checking the spec, I notice that the CSRF token
is passed under javax.faces.Token request parameter, but the javascript
documentation should "relay" the token like it does with
javax.faces.ViewState or javax.faces.ClientWindow if and only if
the token is present.
I created this issue in order to fix it:
http://java.net/jira/browse/JAVASERVERFACES_SPEC_PUBLIC-1157
regards,
Leonardo Uribe