This is part of one of the possible ways to prevent against attacks such as sub - forgery.
It can be used in the Synchronizer Token Template .
It can also be used in the "Double cookie sending" method mentioned at the bottom of the page linked above.
source share