coates’s avatarcoates’s Twitter Archive—№ 4,063

  1. …in reply to @brianlmoon
    brianlmoon I wonder if it actually matters. In a properly designed CSRF system, non-malicious end-users should never see the error.