Full threadnewgrad·Hmm, I don't understand why the author said that if we use OAuth, having CSRF protection does not make sense. Does anybody know why?View on HN