Check CSRF posture across every form and mutation API. Pracht enforces
same-origin on mutation API requests by default (`api.requireSameOrigin`); this
verifies the default is intact and that cookies, middleware, or tokens cover
what it does not.
Use for "audit CSRF", "check CSRF protection", "are forms safe", "review session
security".