Why do some websites implement their logout link as a form post via JavaScript versus a plain old GET request?
16th October 2010
My answer to Why do some websites implement their logout link as a form post via JavaScript versus a plain old GET request? on Quora
Probably because if you implement logout as a GET action, I can force you to log out of a site by tricking you in to visiting a page with an <img src="http://yoursite.com/logout/" width="1" height="1"> element on it.
More recent articles
- Video: Building a tool to copy-paste share terminal sessions using Claude Code for web - 23rd October 2025
- Dane Stuckey (OpenAI CISO) on prompt injection risks for ChatGPT Atlas - 22nd October 2025
- Living dangerously with Claude - 22nd October 2025