Tweaked the controller to use 'protect_from_forgery' properly