Using CSRF token in rest API is helpful or not ? as far as I know we don\'t have a session so we should send the token to client for next request or for submitting the form.