Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I think you're correct here. Also, like POST-based CSRF, get-based CSRF is also a solved problem (issue a param in the URL)


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: