Comment on Why does Google prepend while(1); to their JSON responses?parentComments−hdhzy9yJS can't (that protects against stealing the token) but the server still receives it even when the request originates from foreign domain. That's the gist of CSRF [0].[0]: https://en.wikipedia.org/wiki/Cross-site_request_forgery
Comments
JS can't (that protects against stealing the token) but the server still receives it even when the request originates from foreign domain. That's the gist of CSRF [0].
[0]: https://en.wikipedia.org/wiki/Cross-site_request_forgery