Because if not, any requests made by non-browsers are still susceptible and will only give users a false sense of security.