https://docs.djangoproject.com/en/stable/ref/csrf/
https://flask-wtf.readthedocs.io/en/stable/csrf.html