upon testing it seems that to do `renew` and `terminate` request, the `_csrf` cookie has to be set to `value`