CSRF protection with CORS Origin header vs. CSRF token CSRF protection with CORS Origin header vs. CSRF token javascript javascript