https://github.com/pillarjs/understanding-csrf#how-does-a-csrf-attack-work
A CSRF attack works because browser requests automatically include all cookies including session cookies.
https://github.com/pillarjs/understanding-csrf#how-to-mitigate-csrf-attacks
cookie + token: https://security.stackexchange.com/questions/51188/cookiesession-based-csrf-protection