"website.layout" inherit of "portal.frontend_layout" which inherit of "web.layout" which contains the creation of the CSRF token. Add because "website.layout" add a t-cache key, the CSRF token is under this cache key. But the CSRF token should be always generated, then add t-nocache on CSRF token t-set. Part-of: odoo/odoo#95755