Returning a known-good token is not part of the trait method because I
think handlers other than the ones based on the action API wouldn't even
need a token if the session is safe against CSRF.
Bug: T305043
Change-Id: If41749722b28c8c0e9898b3d3e7937167653fb10