added CSRF protection and started moving actions that need it to POST, which automatically inherits CSRF protection. Not complete yet