Twitter started using a bigger (80 instead of 16 bytes) CSRf token for logged in users, and expects those to be used as 'x-csrf-token' header when send via 'ct0' cookie. Generating an 80 byte token ourselves doesn't work, and Twitter will still insist on using its own.
27 KiB
27 KiB