{# DOM-readable CSRF token for fetch POSTs: the csrftoken cookie is HttpOnly in production (settings.SECURE), so TH.getCsrfToken falls back to this. #}