fix: enable / disable setting + complete cleanup
The correct CSRF standard was adhered to. CSRF only applies to push, post, delete. The entire GET has been removed. There will be a separate module which implements this via jwt.
Related: #2 (closed)