closes #7223
closes #7050
See http://guides.rubyonrails.org/security.html#cross-site-request-forgery-csrf