Premier League Predictor: Django & MySQL — Chapter 4, Exercise 2 ==================================================== TASK Explain why @ensure_csrf_cookie is needed on fixture_entry even though that view renders no traditional HTML form, and what would happen to the Add Fixture button's own fetch call if the X-CSRFToken header were left out entirely. SOLUTION Django normally sets its CSRF cookie as a side effect of rendering the {% csrf_token %} template tag inside a real HTML