* [api] Fix, don't exempt CSRF on APIs * adds cookie based CSRF token support * blacking Co-authored-by: ʈᵃᵢ <tdupreetan@gmail.com>