* get_random_bytes: use PHP7 random_bytes() if it is available * validate CSRF token using hash_equals