Simon Willison’s Weblog

Items tagged quora, security, webdevelopment, rest

Filters: quora × security × webdevelopment × rest ×

Why do some websites implement their logout link as a form post via JavaScript versus a plain old GET request?

Probably because if you implement logout as a GET action, I can force you to log out of a site by tricking you in to visiting a page with an <img src="" width="1" height="1"> element on it.

[... 64 words]