By restricting role changes to POST requests, which they should be anyway, we get all the rails CSRF protection for free.