Why do some websites implement their logout link as a form post via JavaScript versus a plain old GET request?
16th October 2010
My answer to Why do some websites implement their logout link as a form post via JavaScript versus a plain old GET request? on Quora
Probably because if you implement logout as a GET action, I can force you to log out of a site by tricking you in to visiting a page with an <img src="http://yoursite.com/logout/" width="1" height="1"> element on it.
More recent articles
- My fireside chat about agentic engineering at the Pragmatic Summit - 14th March 2026
- Perhaps not Boring Technology after all - 9th March 2026
- Can coding agents relicense open source through a “clean room” implementation of code? - 5th March 2026