提示提示 1查看先用 `user/password123` 登录提示 2查看检查转账端点是否有 CSRF token 等保护提示 3查看登录后打开其他页面 `attacker.html`,观察会发生什么