CSRF protection and JSON