> Essentially all applications that use cookies for authentication need to protect against CSRF.
Not just cookies!! Any HTTP authentication. Kerberos, NTLM, OAuth.