Indeed! Thanks @bestmomo really appreciate the detailed answer and it seems to fix the problems.

When loading in the latest dev copy of L5 though the CSRF implementation seem to have switched around again to be non default, a better approach if you asked my personal opinion.

