• We shouldn’t encourage disabling csrf_protection!!

    If it happens in AJAX calls, need to send the CSRF value & name with AJAX calls.