* Set CSRF on as the default for new installs. Not sure we can impact config on existing installations. * Fix the spelling mistake that I noticed after editing this.