Merge pull request #3134 from kdazzle/patch-1

Return 403 instead of 500 if no CSRF token given