Add checks and restrictions to AJAX endpoint

Merged mattwire requested to merge mitigateajax into 6.3.2

Merge request reports