Autorize has two modes of defining the credentials for the low-privilege user: replacing headers or queries. What about both? I have an application that sends the CSRF in the header and as a body parameter on POST requests.