But now that we are talking about it.. I read that...
# ktor
s
But now that we are talking about it.. I read that document earlier today and could not find a reason for the second requirement (the CSRF token). Why isnt the origin checks enough?