Why can't a malicious site obtain a CSRF token via GET before attacking? Why can't a malicious site obtain a CSRF token via GET before attacking? ajax ajax