3 ms·
This just highlights how the security scanning is just theater though. So bad actors can now just have their evil content behind a form, and users get accustome
by badmintonbaseba 2y ago
This just highlights how the security scanning is just theater though. So bad actors can now just have their evil content behind a form, and users get accustomed to the double opt-in workflow anyway.
- arkh 2y agoYup, best thing would be to either have a form in your email / SMS or let's get crazy: implement POST links (and maybe DELETE ones too). Your client knows it will change things when followed (so security clients and prefetchers won't open it), the server receive a POST request, and it's a one click action for the user.