Hacker News new | ask | show | jobs
by Ergomane 4787 days ago
The "one-click to activate one time" links should always lead to a page where the user has to perform a POST to prevent "smart" applications from using the token when trying to show a thumbnail / preview or offer other services.

eg KDE (old) http://drupal.org/node/24398