use hmac_sha256 when assembling csrf token