Reverts to changeset 435, and just add {% csrf_token %} to template forgot_pw.html, since CSRF protection seems to be only here (surely because of django.contrib.auth.views).
<form id="test" class="wizard-form" action="." method="post">
{{ form }}
<input id="sub" name="continue" type="button" value="finish →"/>
<script type="text/javascript">
$(function() {
$("#sub").click(function () {
var str = $("#test").serialize();
$.post("{% url test_inner %}", str,
function(data, textStatus){
$(".ui-tabs-panel").not('.ui-tabs-hide').html(data);
}, "html");
});
});
</script>
</form>