Full threadrichardhenry·This isn't really a CSRF attack, and serving up content specific to the current user through a JavaScript file is an odd practice to begin with.View on HN