3 ms·
That's simply because of historical compatibility. What you're describing is what a basic HTML form does - and despite it representing a CSRF risk, it can't be
by BillinghamJ 5y ago
That's simply because of historical compatibility. What you're describing is what a basic HTML form does - and despite it representing a CSRF risk, it can't be removed. As such, it's standard practice to protect against CSRF attacks