Reverts to changeset 435, and just add {% csrf_token %} to template forgot_pw.html, since CSRF protection seems to be only here (surely because of django.contrib.auth.views).
hasPerm = function(label) {
return (-1 != CY.Array.indexOf(sv_user_permissions, label)) ;
}