Simon Willison’s Weblog

Items tagged quora, security, javascript, rest

Filters: quora × security × javascript × rest ×


Why do some websites implement their logout link as a form post via JavaScript versus a plain old GET request?

Probably because if you implement logout as a GET action, I can force you to log out of a site by tricking you in to visiting a page with an <img src="http://yoursite.com/logout/" width="1" height="1"> element on it.

[... 64 words]

Types

Years

Tags