Content behind a JS shell — crawl JS with katana or capture with mitmproxy/Burp, then replay the internal call with session cookie + CSRF header. Co-Authored-By: Kai <kai@djeditech.com>