Reverts to changeset 435, and just add {% csrf_token %} to template forgot_pw.html, since CSRF protection seems to be only here (surely because of django.contrib.auth.views).
<html>
<head>
<title>Combo Box Demo</title>
<script type="text/javascript" src="combo-box.js"></script>
</head>
<body>
<p>This is a sample of how to use the combo box.</p>
<form action="/" method="get">
<select name="editable" onKeyPress="edit(event)" onBlur="this.editing =
false;">
<option>To create a new option, just start typing</option>
</select>
</form>
</body>
</html>