ParentFull threadbluefinity·You can do the same thing with POST by submitting a form with JS. The correct way to protect against this sort of thing is to use a CSRF token.View on HN