[#7906] in login post, pass a _session_id value in both POST and cookies, so it gets past CSRF checks
1 file changed