. . "The half that is the CSRF is making sure they are logged in so that the XSS will do anything other than just pop up an alert box or something else annoying." . . .