This adds a middleware which, when activated, will deny any form submission which does not include a valid `authenticity_token` parameter or `http-x-csrf-token` header with the request.
The header and parameter names are identical to the ones supported by Ruby's rack-protection gem for interoperability purposes.