About this question
How does the X-CSRF-Token work?
I read in a blog that the X-CSRF token is added to the request HTTP header for AJAX requests. To use it, we can put the csrf value in a <meta> tag while rendering the HTML, then in the front end we can get the value from that <meta> tag and send it to the backend.