Hacker News new | ask | show | jobs
by richardhenry 5207 days ago
This isn't really a CSRF attack, and serving up content specific to the current user through a JavaScript file is an odd practice to begin with.