Is there any reason a read-only API shoud use a CSRF token?

After learning about CSRF, I feel like probably not, because IIUC, the malicious site cannot actually view the response, they can only send responses on behalf of a user via the browser.

submitted by /u/null_endian
[link] [comments]

from hacking: security in practice
