Coming soon — this article is being prepared. Below are its question, intended outcome, and place in the story.
The question
How can you reject requests without a session-bound CSRF token?
What we will work through
Reject requests without a session-bound CSRF token.
Before you begin
Previously covered: How automatically sent credentials enable CSRF.