Used session identity in hidden input field to validate the request is coming from the user intentionally.