CreationForm should check for the presence of a CSRF token in the request, and it's validity.
Warning messages should be displayed when it's missing/not valid