CSRF mitigation

referer spelling is intentional here since there was a spelling mistake in specifications and no one corrected it before it got published.

Last updated