Thrown by the form-CSRF verifier when the submitted token is absent or does not match the session's token.
The middleware catches this and answers 403; it is exported so an
application that installs the verifier itself can distinguish a CSRF failure
from other rejections.
readonly
name: string
Discriminant for consumers that cannot use instanceof across realms.