Added CSRF route protection

Closes #3506413

Merge request reports

Loading