Do login forms need tokens against CSRF attacks? Do login forms need tokens against CSRF attacks? php php