5 ms·
Poorly designed applications like this one? https://accounts.google.com/Logout https://accounts.google.com/Logout
by mherkender 13y ago
Poorly designed applications like this one? https://accounts.google.com/Logout https://accounts.google.com/Logout
- jodrellblank 13y agoYes. What's your point? Google must be incapable of poor design? Everything a big company does is good?
- mherkender 13y agoI wanted to know what HN consensus was on this sort of thing, because it seems to me this is not something that inexperienced programmers do (like SQL injection). Also, full disclosure: I work for Google.
- windsurfer 13y agoYes. Imagine if everyone put the following code on their sites: <iframe src="https://accounts.google.com/Logout" width="0" height="0" ></iframe>
- snikch 13y agoI believe that would be the point of <meta http-equiv="X-Frame-Options" content="deny">
- codygman 13y agoThat's like trying to duct tape your arm back on after losing a fight with a chainsaw.
- mike-cardwell 13y ago<img src="https://accounts.google.com/Logout" https://accounts.google.com/Logout" style="display:none"> "X-Frame-Options" is used to defend against click-jacking attacks, not to defend against CSRF.
- mike-cardwell 13y agoYou could do the same with a POST by just running the following in a hidden iframe on your site: <form id="form" method="post" action="https://accounts.google.com/Logout"></form> <script>$('#form').submit()</script> The correct way of dealing with this issue is to rely on CSRF tokens.