Some more test data for you...
Experienced false alarm CSRF problem trying to access link to unwatch message thread from email.
Good luck with the troubleshooting!
-------------------------
Test report:
Windows XP
> started chrome (Version 24.0.1312.57 m)
> pasted
https://permies.com/forums/posts/unwatch/21364 into browser
login screen displayed
> entered username and password
https://permies.com/templates/csrf.html was displayed
> started IE8
> pasted
https://permies.com/forums/posts/unwatch/21364 into browser
login screen displayed
> entered username and password
https://permies.com/templates/csrf.html was displayed
> started Firefox (Version 17.01)
> pasted
https://permies.com/forums/posts/unwatch/21364 into browser
login screen displayed
> entered username and password
https://permies.com/templates/csrf.html was displayed
BUT n.b. it seems I have been authenticated (and may well have been on the IE and Chrome previous tests): e.g. I can go to
https://permies.com/t/21220/tnk/system-oddness and see an active link to post a reply.