I believe the fix for this (checking if the request is xhr) hasn't been committed yet.
See http://weblog.rubyonrails.org/2011/2/8/csrf-protection-bypas...
I was under the impression that trying to validate that was ultimately as fragile as checking the user-agent string...