CSRF: http://en.wikipedia.org/wiki/Cross-site_request_forgery rails-CSRF: http://guides.rubyonrails.org/security.html#cross-site-request-forgery-csrf