http: Add some helpful comments regarding auth/CSRF default tip

(0) -10 -1 tip

mercurial