The approach is to use per-session CSRF tokens - this avoids many complications related to per-form tokens. We generate a sequence of hashes based on session IDs that doesn't follow the same pattern as normal database API IDs by supplying a "kind" parameter to encode_id (we use the same pattern for securing the job files API for Pulsar).