Can “Cookie to header token” CSRF prevention be beaten with permissive CORS? | Heykuki News