Is an X-Requested-With header server check sufficient to protect against a CSRF for an ajax-driven application? April 11, 2024 by Tarik