Hi, How does Confluence mitigate Cross-Site Request Forgery on login? I have a confluence instance that doesn't seem to have a CSRF token on login. Is that just a configuration error, or does Confluence handle CSRF in some other way? Best regards