CSRF defense for web applications. Use when tasks involve CSRF tokens, SameSite, cookie-authenticated requests, browser forms, state-changing endpoints..