Yeah, the cookie will be sent automatically with all requests by the browser. So only using a token in a cookie defeats the whole purpose of CSRF defence.
確定! 回上一頁