CSRF in the logout handler