3 ms·
You're probably right. I'll change that. Apart from the REST argument, the best single reason I can come up with to justify changing these to use POST is that
by xavi 14y ago
You're probably right. I'll change that.
Apart from the REST argument, the best single reason I can come up with to justify changing these to use POST is that otherwise it's possible to cancel an email change or resend a confirmation of a logged in user by having him load a page containing an image tag like <img src="url-to-cancel-email-change" /> . This is the same reason for which noir-auth-app handles logouts through POST instead of GET. Not really dangerous I guess, annoying at most, but worth to fix it anyway.
By the way, in twitter.com (and I guess a lot of other not so popular websites) these are handled as GETs, and so they're subject to this kind of "attacks".
Thanks for raising the issue.
- graue 14y agoI suppose these particular paths aren't as exploitable as a logout (which isn't a GET on Twitter, either, it seems), but what about, e.g., Chrome's link prefetching? I'm not sure how it would know not to prefetch, for instance, the "cancel email confirmation" link. Anyway, I'm teaching myself Clojure right now and this looks like great sample code to study, so thank you for sharing it.
- xavi 14y agoFrom what I understand, Chrome doesn't prefetch HTTPS URLs https://developers.google.com/chrome/whitepapers/prerender https://developers.google.com/chrome/whitepapers/prerender but Firefox does https://developer.mozilla.org/en-US/docs/Link_prefetching_FAQ#Are_there_any_restrictions_on_what_is_prefetched.3F https://developer.mozilla.org/en-US/docs/Link_prefetching_FA... So, using HTTPS could be a way to avoid prefetching, but it would not always work. In any case, I've already committed the changes that you suggested, so now noir-auth-app is free from these problems.