* remove explicit CSRF-token handling * use NEXTAUTH_SECRET secret to better comply with nextAuth standards * update next.js and nextAuth * remove ECR github action * add name to mail-from