Addressing CSRF from a Python service

This is quite strange. If you’re able to put this together as a reproduction (a git repo or codesandbox.io sandbox or something with clear instructions about how to see it) and post a link here or as a new issue on the apollo-server repo, we’d be happy to look into it further.