EXERCISE 3 — How "require application/json" CSRF protection still fails ======================================================================= THE INTENDED DEFENCE: The API rejects state-changing requests unless Content-Type is application/json. Reasoning: an HTML