* disabled CSRF protection for login route
* return CSRF token from login and retransmit it during module upload
``deploy`` only sends CSRF token if given one by authenticate so that
the command can be used for non-updated modules.
Closes#9488
Checks that the provided user (or user in the provided dataset):
* is the superadmin
* or is a member of group_erp_manager
There are a number of hand-rolled "is_admin" checks in the codebase some
of which are fairly gnarly. The shortcut provides a single point of
contact, avoids forgetting about cases (e.g. SUPERUSER_ID) and is
relatively convenient when checking a user which is not the "current"
user.
closes#8146