A POST the browser demonstrably sent — correct token, correct body — left no trace: no CSRF termination, no fatal, and no action log. Rejected-before-PHP and died-inside-the-include are indistinguishable from outside, so the first statement now records that execution arrived.