Specifically in Rails apps, we look for root ActionController classes without a call to `protect_from_forgery`.