Cookie-based session protection
Access and refresh tokens are issued in HttpOnly cookies. State-changing cookie-authenticated requests pass CSRF validation.
AuthCookies · CsrfMiddleware
The CSRF double-submit cookie is readable by the browser by design; authentication cookies are not.