[Improvement] Added "lost password confirm" as a do-not-cache page. [Improvement] Misc code improvements. [Bug Fix] Logged-in cookie is now cleared when a visitor is logged-out due to a session timeout. [Bug Fix] Visitors automatically logged-in from the "forgot my password" submission page are now correctly detected as non-guest visitors.
[Bug Fix] Csrf validation is now bypassed for 'AddReply' and 'PostThread' guest actions to avoid security errors when performing these actions from a cached page. (Applies to XF 2.2 'write before registering' feature)