pub fn check_csrf(headers: &HeaderMap, expected: &str) -> Result<(), AdminError>
Compares the request’s X-CSRF-Token against the session’s, in constant time.
X-CSRF-Token