e8da858e0e
Per https://github.com/OWASP/railsgoat/wiki/R4-A8-CSRF this line should be commented out for the developer to fix (by uncommenting it).