Hi there,

I am considering rewriting and (hopefully) simplifying the CSRF middleware. 
While looking through the code I realized that we put stuff into 
request.META as well as attributes on the request object itself 
(csrf_cookie_needs_reset) for instance. Is there any reason why we do not 
stick to one format?

Or more generally put: When should middlewares write into META as opposed 
to a attribute.


