Since this is a valid option, this should be implemented, so that one can decide in which session the csrf Token is stored.