Put.io API design issues
miki.it
miki.it
But remember: as soon as you use cookies (or anything else the browser sends by itself automatically), you need to make sure that you know that your user initiated the request, or else you get XSRF issues.
And combined with JSONP, this is basically game-over. However, when the cookie-based auth is removed, I see no problems with JSONP (for the server; the one using the JSONP has to have trust in the server to not set malicious code).
A thousand times this.
I used to give a talk about basic web application security, and my favourite part of that talk was right after explaining CSRF when I'd point out that "... and if you don't have active protection in place against this attack, your app is vulnerable right now". You could almost see people's faces turning white in the audience.
[1]https://www.owasp.org/index.php/Cross-Site_Request_Forgery_%...