https://systw.net/note/archives/1297
CSRF bypass referer