|
|
|
|
|
by nothrabannosir
3780 days ago
|
|
But.. that's exactly what while(1); and friends in json responses protect you against? someone overriding the Array constructor function and including your JSON resource from a <script src=…> ? So this is, in fact, CSRF? |
|