- remove sessions - remove all references to csrf - create a shared base model for the 2 types of token