csrf ongoing work (#1803)