4 ms·
The logout link is rendered with the token in its query string
by philmander 11y ago
The logout link is rendered with the token in its query string
- VoidWhisperer 11y agoWouldn't this still allow logging in without consent if they aren't logged in?
- Osiris 11y agoI have implemented CSRF for the public API I work on and all PUT/POST requests require the CSRF token, not GET requests. In this case, the login form uses a POST request and thus must require a CSRF token to avoid an attack on users that aren't logged in.
- dang 11y agoIt does. We haven't rolled out the fix that Nick described (https://news.ycombinator.com/item?id=11178922 https://news.ycombinator.com/item?id=11178922) because it will probably break a bunch of the third party apps and scrapers that give people alternative interfaces to HN. Those have value and I'd rather not make their lives more difficult unless/until it's necessary.
- qjighap 11y agoFinally, some clarification on which hacker news it is. I care less about the hacker news with the "the"