Why do we have both CSRF protection and CORS?