I get this occaisionally, after "logging in correctly" about 3 times you get the CRSF error, but you are technically logged in, the login redirects you to login.php for some reason.. which could be the issue. Dunno, will have a look when I get the chance, for now, when you see that error, you can simply delete login.php from the url, and it will present you with the normal logged in view. ;-)